FIDO2 / WebAuthn
FIDO2/WebAuthn: Attestation, Metadata Service (MDS3) and Trust

FIDO2 / WebAuthn FIDO2-Enterprise-Attestation: Enterprise Attestation and AAGUID Allowlisting

Enterprise attestation per WebAuthn L3 6.5.4 + CTAP2.1. Standard attestation is ANONYMOUS per AAGUID batch (so individual authenticators are not identifiable) to protect privacy. ENTERPRISE ATTESTATION carries the AUTHENTICATOR-UNIQUE IDENTIFIER (e.g. serial number) in the attestation statement, allowing enterprise managed-device deployments to track individual hardware authenticators. REQUIREMENTS: (a) authenticator MUST support enterprise attestation as a feature; (b) authenticator MUST be configured by the device manufacturer or enterprise + tied to a specific RP ID (vendor-facilitated) OR by enterprise platform configuration (platform-managed) to release enterprise attestation only to authorised RPs; (c) client + browser MUST support + honour enterprise attestation per attestation = enterprise option; (d) RP MUST verify enterprise attestation flag + the unique identifier matches the enterprise inventory. PRIVACY: enterprise attestation degrades user privacy by enabling per-authenticator tracking + should be limited to managed-device + enterprise-RP combinations; consumer + bring-your-own scenarios should use attestation=none or basic. AAGUID ALLOWLISTING: enterprise RPs may allowlist specific AAGUIDs to enforce hardware-vendor + model-specific deployments + integrate with device inventory.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in FIDO2/WebAuthn: Attestation, Metadata Service (MDS3) and Trust

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.