The settingWhat we hold this to
CreativeTechs minimum
FIDO2 / passkey method state = enabled. A CA policy in state ENABLED on directory roles with authentication strength = Phishing-resistant MFA. Fleet-wide user coverage is a later phase.
Benchmark position
CISA MS.AAD.3.1 (Entra ID P1) — phishing-resistant authentication strengths required. CISA applies it to all users; we apply it to admins.
Where we differ, and why
A deliberate gap from CISA, and worth stating plainly: phishing-resistant for everyone is the right destination, but the enrolment cost lands on the client. Admins first is where the value concentrates. Touch ID passkeys on Apple hardware make the eventual fleet-wide move cheaper for us than for most MSPs.
Where the switch is
Entra admin centre → Protection → Authentication methods → Policies → Passkey (FIDO2). Strength: Protection → Conditional Access → Authentication strengths.
How to verify
Graph: /policies/authenticationMethodsPolicy/authenticationMethodConfigurations('Fido2') → state eq 'enabled'- Why it matters
- The only thing that reliably stops adversary-in-the-middle phishing, which is what currently defeats Authenticator push.
- How we check
- Maester CISA.MS.AAD.3.1 — authentication strength.
- Fix — M365
- Entra → Authentication methods → enable FIDO2 / passkeys. CA policy → authentication strength = phishing-resistant MFA, scoped to admins first.
- Fix — Google
- Admin → Security → 2SV → allow only security keys, then enforce.
- User notices
- Enrolment effort, plus hardware keys or platform passkeys.
- Expected pushback
- Real but shrinking — and being an Apple shop is the advantage. Touch ID passkeys on Macs and iPhones are native, free and genuinely pleasant, which is a better story than most MSPs can tell.
- Reason on file
- Admins first; Touch ID makes this cheap on Apple hardware. Fleet-wide is a later phase.
