Why: An MFA rollout runs an authenticator lifecycle whether it means to or not: verifying who is enrolling, registering keys and passkeys, replacing lost ones, revoking at departure. Done deliberately, that routine advances the issuance, protection, and revocation elements of this requirement for the factors the practice deploys.
What this does not claim: The requirement spans every authenticator type — passwords, certificates, tokens, device secrets — plus default-credential changes and organization-defined refresh, most of which sit outside an MFA deployment. May partially address the requirement for the authenticators the practice issues; the rest of the lifecycle needs its own procedures.
- Verify identity before MFA enrollment and re-enrollment
- Define and operate the lost-key replacement and departure-revocation path
- Record authenticator issuance and revocation against joiner and leaver events
- Enrollment-verification procedure and records
- Revocation records tied to departures
- Registered-authenticator reports from the identity provider
Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06