Why: FIDO2 and passkey authenticators — the methods this practice deploys — are replay-resistant by construction, so the practice advances this requirement for every access path it converts.
What this does not claim: May partially address the requirement: replay resistance must hold for all network access, including service accounts, legacy protocols, and paths the MFA rollout never touches. Those need their own analysis within the organization's defined system boundary.
- Prefer WebAuthn-based factors over push or code-based ones during rollout
- Disable NTLM and other replayable legacy protocols as enforcement expands
- Authentication-method policy showing WebAuthn factors
- Legacy-protocol disablement configuration
Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06