Why: FIDO2 and passkey authenticators — the methods this practice deploys — are replay-resistant by construction, so every access path the rollout converts advances this requirement as a side effect of the factor choice.
What this does not claim: Rev. 3 phrases the requirement across all access to accounts, and replay resistance must hold on paths the MFA rollout never touches — service accounts, legacy protocols, appliance logins. May partially address the requirement; the untouched paths need their own analysis within the defined system boundary.
- Prefer WebAuthn-based factors over push or code-based ones during rollout
- Disable NTLM and other replayable legacy protocols as enforcement expands
- Authentication-method policy showing WebAuthn factors
- Legacy-protocol disablement configuration
Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06