this post was submitted on 13 Dec 2023
1 points (100.0% liked)
Cybersecurity
9 readers
45 users here now
An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!
Rules
Community Rules
- Be kind
- Limit promotional activities
- Non-cybersecurity posts should be redirected to other communities within infosec.pub.
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
It is possible to restrict FIDO2 keys enrollment by their AAGUIDs. Not something the general public will encounter, but a business using FIDO2 keys as their MFA can limit which hardware can be used, for example limit the enrollment to specific AAGUIDs from Yubico
https://support.yubico.com/hc/en-us/articles/360016648959-YubiKey-Hardware-FIDO2-AAGUIDs
That's something I had to look into when configuring our Azure environment.