Why: The practice's core activity — enforcing phishing-resistant multifactor authentication starting with privileged and remote-access accounts — works on the same population and mechanism this requirement names. The practice's method choice (FIDO2, passkeys, PIV) sits above the requirement's floor.
What this does not claim: Supports implementation of the requirement; it does not satisfy it on its own. The requirement spans every account and access path in the assessed boundary — including local privileged access and systems outside the identity provider — and an assessor evaluates scope and evidence, not intent. Phishing resistance is a method choice within the requirement, not a substitute for its coverage.
- Enroll and enforce phishing-resistant MFA for administrators and remote access first, then the workforce
- Block legacy authentication protocols that bypass a second factor
- Track enrollment coverage by privilege tier with dated exceptions
- Identity-provider enforcement policy export
- Monthly coverage report by privilege tier
- Sign-in logs showing legacy-protocol attempts at or near zero
Where this holds: Holds wherever accounts live in an identity provider that can enforce factor policy; weakens for standalone and appliance-local accounts, which need separate treatment.
Review status: Technical review complete · Reviewed by inDirectIT practitioner review — CUI security and NIST SP 800-171 engineering · updated 2026-08-06