Skip to content
ControlVerdict
IA.L2-3.5.4addresses
IA.L2-3.5.4Replay-resistant Authentication
Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts.
  • [a]

    replay-resistant authentication mechanisms are implemented for network account access to privileged and non-privileged accounts.

View full control

Network access requires FIDO2 or certificate; OTP not accepted for VPN or SSO

ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
Community is just starting — add yours. No verdicts yet.

Implementation

AO coverage. Addresses all replay-resistant authentication objectives for this practice.

Policy. Authentication strength for all CUI applications and the VPN requires a phishing-/replay-resistant method: FIDO2 security key, platform authenticator bound to a compliant device, or device certificate (EAP-TLS) for the VPN. Authenticator-app TOTP and SMS are enrolled for account recovery only and are excluded from the strength used by CUI Conditional Access / VPN policies.

Enrollment. New hires receive two FIDO2 keys (primary + backup) before CUI access is granted. Platform authenticators are allowed only on MDM-enrolled, encrypted endpoints. Lost-key process: disable the credential in the IdP within one business day; temporary access uses the backup key only—no temporary SMS bypass for CUI apps.

VPN. Client certificate issued by the org CA via MDM; password+OTP VPN profiles are removed. Split tunnel is disabled for the CUI routes.

Maintenance. Monthly authentication-methods report for privileged and CUI-group users (methods in use). Quarterly purge of stale device certificates. Annual tabletop of lost-key and break-glass FIDO2 procedures.

Accepted gap. Two partner portals that we must use cannot accept FIDO2. Users reach them only through a browser on a PAW after phishing-resistant SSO to the PAW; partner passwords are vaulted and not reused.

What the evidence looks like

  • Authentication strength / Conditional Access export listing allowed methods
  • VPN profile showing certificate auth and no OTP profile
  • Enrollment checklist and key inventory (serial ↔ person)
  • Sign-in logs showing method claims for a sample of CUI app access
  • Exception register for the two partner portals

Environment

Hybrid workforce; CUI apps behind SSO and a full-tunnel VPN for a small on-prem lab.

Tools

Was this example useful?

Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.

Discussion(0)

No discussion on this example yet

Verdicts capture a conclusion. Use a thread when the interesting part is the argument.

Sign in to start a thread.