TL;DR: The DoW CIO’s new MFA memo approves device-bound FIDO2 passkeys on YubiKeys for DoD use cases, clarifies DoD PKI as the primary credential, and expands guidance across shared devices, BYO mobile, and privileged access scenarios, according to Yubico. The policy shift matters because it removes ambiguity around passwordless authentication, but identity teams still need to map use cases, credential lifecycle, and device-bound assurance to their own governance model.
NHIMG editorial — based on content published by Yubico: the DoD MFA memo and approved device-bound FIDO2 passkeys
Questions worth separating out
Q: How should security teams roll out passkeys without creating support problems?
A: Start with recovery design, user communication, and help desk readiness.
Q: Why do strong authenticators still need identity governance?
A: Strong authenticators reduce one class of attack, but they do not manage registration, device replacement, help desk recovery, or exception handling.
Q: What breaks when passwordless access is added to privileged workflows without a lifecycle model?
A: Issuance, revocation, and fallback handling become inconsistent, especially when one device holds multiple credentials and one user may move across shared, personal, and privileged contexts.
Practitioner guidance
- Define the primary credential model Document whether PKI, CAC, or another credential is primary for each environment before expanding device-bound passkeys into production use.
- Segment policy by device ownership Create separate issuance, recovery, and revocation rules for shared government devices, BYO mobile devices, and privileged workstations.
- Map privileged access to explicit authenticator rules Require a named approval path for IT privileged users so passkey adoption does not blur into uncontrolled elevated access.
What's in the full article
Yubico's full post covers the operational detail this post intentionally leaves for the source:
- The specific DoD use cases where device-bound FIDO2 passkeys are authorised.
- The credential combinations supported on a single YubiKey for PKI and FIDO2.
- The practical distinctions between shared government devices, BYO mobile devices, and privileged users.
- The memo language around DoD PKI, CAC examples, and the 2019 mobile PKI requirements.
👉 Read Yubico's analysis of the DoD MFA memo and approved passkeys →
DoD MFA memo and FIDO2 passkeys: what changes for IAM teams?
Explore further
Policy clarity is now part of authentication security. The memo matters because it converts device-bound FIDO2 passkeys from a general security concept into an explicit authorised path for defined DoD scenarios. That removes one of the most common governance blockers, which is uncertainty about whether a given method is actually approved for the intended use case. For practitioners, the lesson is that authentication modernisation fails when policy language lags the control it is supposed to govern.
A few things that frame the scale:
- Only 19.6% of security professionals express strong confidence in their organisation's ability to securely manage non-human workload identities, according to The 2024 Non-Human Identity Security Report.
- 88.5% of organisations acknowledge that their non-human IAM practices lag behind or are merely on par with human IAM efforts, which is why credential governance remains a maturity gap.
A question worth separating out:
Q: Who is accountable when device-bound passkeys are used across shared and personal devices?
A: Accountability should sit with the identity and access governance function, because the real issue is not the hardware token alone but the policy that defines where it is valid, who approves it, and how it is recovered. That model should be reviewed alongside privileged access and certificate governance.
👉 Read our full editorial: DoD MFA memo changes the case for phishing-resistant passkeys