Skip to main content

Authentication Method - FIDO2 security key - Enforce key restrictions

Manages if registration of FIDO2 keys should be restricted.

NamekeyRestrictions.isEnforced
ControlAuthentication Method - FIDO2 security key
DescriptionDefine configuration settings and users or groups that are enabled to use FIDO2 security keys
SeverityLow

How to fix

Microsoft Learn - Enable passkeys (FIDO2) for your organization: Enforce key restrictions

Details of configuration item

RecommendationRestrict usage of FIDO2 from unauthorized vendors or platforms
Configurationpolicies/authenticationMethodsPolicy/authenticationMethodConfigurations('Fido2')
SettingkeyRestrictions.isEnforced
Recommended Value'true'
Default Valuefalse
Graph API Docsfido2AuthenticationMethodConfiguration resource type - Microsoft Graph v1.0 - Microsoft Learn
Graph ExplorerOpen in Graph Explorer