cisagov / ScubaGear

Automation to assess the state of your M365 tenant against CISA's baselines
https://www.cisa.gov/resources-tools/services/secure-cloud-business-applications-scuba-project
Creative Commons Zero v1.0 Universal
1.76k stars 226 forks source link

Update AAD.3.1v1 to include device-bound passkeys language and resource to AAD.3.1 #1431

Open ahuynhMITRE opened 6 days ago

ahuynhMITRE commented 6 days ago

๐Ÿ—ฃ Description

Microsoft Entra ID has added support for device-bound passkeys stored on computers and mobile devices as an authentication method, in addition to the existing support for FIDO2 security keys. This enables users to perform phishing-resistant authentication using the devices that they already have. This PR will add additional language to the description for AAD.3.1v1 and add a new resource link to note this new support.

๐Ÿ’ญ Motivation and context

Change is required to keep the documentation up to date with the new phishing-resistant authentication method now supported in Microsoft Entra ID.

Closes #1203

๐Ÿงช Testing

N/A currently only an SCB update

โœ… Pre-approval checklist

โœ… Pre-merge checklist

โœ… Post-merge checklist