EIDAUTH-006: FIDO2 Security Key Inventory and Audit

Platform
Entra ID / M365
Category
Entra ID Authentication Methods & MFA
Severity
Info
Zero Trust pillar
Identity (weight 1)
Golden fixtures
2
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

FIDO2 security keys provide phishing-resistant authentication but must be inventoried and managed throughout their lifecycle. Untracked keys may remain associated with departed employees or become lost without detection. Regular audits ensure only authorized keys are active and properly assigned to current users.

Recommended value

All registered FIDO2 keys inventoried with documented owner assignments and regular attestation reviews

Remediation

Review FIDO2 key registrations via Entra ID > Protection > Authentication methods > FIDO2 security key. Cross-reference registered keys with your hardware asset inventory and remove keys for departed users. Implement key registration policies that restrict allowed AAGUID values to approved vendor models.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for EIDAUTH-006
ScenarioExpected verdict
cleanPASS
no-dataNot Assessed

Framework mappings

CISA SCuBA
MS.AAD.3.1v1
NIST SP 800-53
IA-2(6)