Why: Rev. 3 restates the multifactor requirement and widens it to all access to privileged and non-privileged accounts — the same populations this practice enforces first. The practice's method choice (FIDO2, passkeys, PIV) is a stronger selection within the requirement, not an addition to it.
What this does not claim: Rev. 3 does not require phishing-resistant methods by name — choosing them exceeds the stated requirement rather than being compelled by it. The widened scope now reaches local access to non-privileged accounts, a path many MFA rollouts leave for last; the practice supports implementation but does not satisfy the requirement on its own, and an assessor evaluates coverage and evidence, not intent.
- Enroll and enforce phishing-resistant MFA for administrators and remote access first, then the workforce
- Extend enforcement to local endpoint sign-in through platform authenticators
- Block legacy authentication protocols that bypass a second factor
- Track enrollment coverage by privilege tier with dated exceptions
- Identity-provider enforcement policy export covering both account tiers
- Coverage report: enforced accounts over active accounts, by tier
- Sign-in logs showing legacy-protocol attempts at or near zero
Where this holds: Holds wherever accounts live in an identity provider that can enforce factor policy; weakens for standalone and appliance-local accounts and for local sign-in paths not yet behind a platform authenticator.
Review status: Technical review complete · Reviewed by inDirectIT practitioner review — CUI security and NIST SP 800-171 engineering · updated 2026-08-06