Because the authenticator has become the possession factor that proves identity. If a lost device is not revoked promptly, or replacement requires too much manual trust, the organisation either risks account takeover or creates pressure to weaken the process. Device lifecycle is therefore authentication governance.
Why device loss changes the trust model in FIDO2
FIDO2 works because the device is no longer just a convenience layer, it is the possession factor that helps prove the user is genuine. That changes device loss from an IT support issue into an authentication event. If a device can authenticate, then losing control of that device means losing control of the trust boundary that the sign-in flow depends on.
For that reason, programmes have to treat loss, theft, retirement, repair, and replacement as part of the authentication design itself, not as a separate operational afterthought. The moment a device is reported lost, the question is not only whether the user can still sign in, but whether the authenticator can still be trusted anywhere else in the estate.
Why replacement workflows often become the weak point
Replacement is where many programmes drift away from the security model they intended to build. If recovery is too strict, users will push for exceptions, fall back to weaker authenticators, or overload help desk processes. If recovery is too permissive, an attacker who has obtained partial personal information or access to recovery channels can use the replacement path to take over the account.
That is why the recovery path has to be designed with the same care as initial enrollment. A good programme distinguishes between routine device replacement, suspected compromise, and high-risk recovery after loss or theft. The Passwordless and Passkeys Guide is useful here because it ties passkey rollout directly to secure recovery design, which is where many deployments fail in practice.
In mature deployments, replacement is also a governance question: who can approve re-enrollment, what evidence is required, how quickly old authenticators are revoked, and whether the new device is allowed to inherit the same assurance level. Those decisions determine whether the organisation preserves phishing-resistant sign-in or quietly reintroduces weaker recovery assumptions.
What strong lifecycle control looks like in practice
Device lifecycle control should be explicit, fast, and auditable. Lost authenticators should be revoked promptly, stale registrations should be removed, and users should not be left with multiple active devices that nobody can explain. The lifecycle process should also make it clear which devices are primary, which are backups, and what triggers re-verification.
For organisations using FIDO2 across laptops, phones, and security keys, device diversity matters. The Workforce Identity Security Guide is relevant because it connects FIDO2 with the broader realities of workforce identity, including account recovery, federation, help desk resets, and session theft. That broader context matters when a lost device is only one part of a wider sign-in and recovery chain.
Operationally, the best programmes verify three things before trusting replacement: the old authenticator is no longer active, the new authenticator is enrolled through a controlled path, and the user’s recovery method does not depend on the same compromised channel. Without those checks, the programme may still be using FIDO2 names and branding, but it is no longer running a robust phishing-resistant design.
Risk and Threat Considerations
Device loss and replacement create a direct account takeover risk because the authenticator itself is the proof of possession. If revocation is slow or recovery is overly manual, attackers may exploit the gap between loss and deprovisioning, or they may target the replacement process through help desk impersonation, stolen recovery data, or social engineering.
Failure mechanism: A lost or stolen authenticator remains accepted, or a new authenticator is issued on the strength of weak identity proofing, enabling unauthorized sign-in or recovery-path abuse.
Impact: The attacker can gain account access without defeating the FIDO2 cryptographic model, and the organisation may be forced to choose between a secure but unusable process and a usable but weaker one.
NIST SP 800-63 Digital Identity Guidelines is relevant because it frames authenticator assurance, binding, and recovery as part of the identity lifecycle, not as a one-time enrollment decision. For programmes at scale, that distinction is what keeps recovery from becoming the back door.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | Digital Identity Guidelines | FIDO2 recovery and authenticator assurance are core digital identity concerns. |
| Recommendation — Align recovery and authenticator binding to the assurance level required for sign-in. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Device loss and replacement depend on lifecycle control of authenticators and their revocation. |
| IA-2 — Identification and Authentication (Organizational Users) | The question concerns workforce sign-in assurance and account access. | |
| IA-8 — Identification and Authentication (Non-Organizational Users) | If external users use FIDO2, their device loss and recovery still affect assurance. | |
| Recommendation — Revoke lost authenticators quickly and govern replacement issuance tightly. Require strong authentication for user access and tie it to controlled recovery. Use appropriate proofing and reauthentication controls for external-user recovery. | ||
Practitioner Guidance
What to prioritise: Treat revocation speed and replacement trust as the main control objectives, not just user convenience. If the programme cannot reliably invalidate a lost authenticator quickly, it is under-controlled even if sign-in itself is phishing-resistant.
What to verify: Confirm that recovery paths are different from ordinary sign-in paths, that backup methods do not collapse into the same failure domain, and that help desk staff have a narrow, documented decision boundary for re-issuing access.
Common mistake: Issuing replacement devices too quickly without first proving the old authenticator is dead. That shortcut preserves user experience in the short term but weakens the assurance story the programme was meant to deliver.
Practitioner takeaway: In FIDO2, lifecycle handling is part of authentication quality. A programme is only as strong as its ability to revoke the old device cleanly and re-establish trust in the new one without widening the recovery path.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org