Skip to main content

Authentication Method - FIDO2 security key - Enforce attestation

Requires the FIDO security key metadata to be published and verified with the FIDO Alliance Metadata Service, and also pass Microsoft's additional set of validation testing.

NameisAttestationEnforced
ControlAuthentication Method - FIDO2 security key
DescriptionDefine configuration settings and users or groups that are enabled to use FIDO2 security keys
SeverityHigh

How to fix

Microsoft Learn - Enable passkeys (FIDO2) for your organization: Enforce attestation

Details of configuration item

Recommendation
Configurationpolicies/authenticationMethodsPolicy/authenticationMethodConfigurations('Fido2')
SettingisAttestationEnforced
Recommended Value'true'
Default Valuetrue
Graph API Docsfido2AuthenticationMethodConfiguration resource type - Microsoft Graph v1.0 - Microsoft Learn
Graph ExplorerOpen in Graph Explorer