What NIST 800-63B Says About Multi-Factor Authentication

Many organizations assume multi-factor authentication (MFA) always requires a password plus a text message, authenticator app, or hardware token. While those approaches can certainly satisfy MFA requirements, NIST Special Publication 800-63B takes a broader view of authentication and recognizes multiple authentication models that provide strong assurance without relying solely on traditional password-based methods.

One section that is frequently overlooked is NIST SP 800-63B Section 5.1.9.1, which describes a Multi-Factor Cryptographic Device Authenticator. NIST states:

“Multi-factor cryptographic device authenticators use tamper-resistant hardware to encapsulate one or more secret keys accessible only through the input of an additional factor, either a memorized secret or a biometric.”

NIST further explains that:

“The authenticator could be a suitably secure processor integrated with the user endpoint itself (e.g., a hardware TPM).”

This distinction is important because it shifts the discussion away from passwords and one-time passcodes and toward cryptographic proof of identity.

What NIST Means by Multi-Factor Authentication

NIST defines MFA as combining two distinct authentication factors. These factors generally fall into three categories:

  • Something you know (PIN or password)

  • Something you have (device or authenticator)

  • Something you are (biometric)

A solution does not necessarily need a password and a one-time code to qualify as MFA. NIST recognizes that stronger authentication can be achieved through cryptographic authenticators protected by an additional factor, such as a PIN or biometric.

What NIST Says About TPM-Based Authentication

NIST specifically identifies the Trusted Platform Module (TPM) as an example of secure hardware capable of protecting cryptographic authentication keys. A TPM is designed to securely store and protect private keys used for authentication and other security operations.

Rather than transmitting passwords across the network, TPM-backed authentication uses cryptographic operations to prove possession of a protected key. Because the private key remains secured within the device, attackers have fewer opportunities to steal reusable credentials.

This approach reduces many of the risks associated with traditional password-based authentication.

What NIST Says About Biometrics

Another commonly misunderstood point within SP 800-63B is the use of biometrics.

NIST explicitly states that biometrics by themselves are not considered authenticators. Instead, biometrics must be used together with a physical authenticator.

In practical terms:

  • A fingerprint alone is not MFA.

  • Facial recognition alone is not MFA.

  • A biometric used to unlock a TPM-protected cryptographic key can satisfy NIST's multi-factor authentication model.

The biometric acts as the second factor required to access the protected credential.

Why NIST Is Moving Beyond Passwords

Throughout SP 800-63B, NIST discusses the weaknesses associated with traditional authentication methods and the threats organizations face every day, including:

  • Phishing attacks

  • Password theft

  • Credential reuse

  • Social engineering

  • Keylogging malware

  • Offline password cracking

  • Replay attacks

NIST repeatedly emphasizes the value of stronger authenticators and cryptographic authentication methods that reduce dependency on shared secrets and passwords.

The publication does not suggest eliminating passwords in all situations, but it clearly promotes authentication mechanisms that are more resistant to modern attack techniques.

Understanding Windows Hello for Business

Windows Hello for Business is one example of an authentication technology that aligns closely with the principles described in NIST SP 800-63B.

When configured correctly, Windows Hello for Business uses a TPM-protected cryptographic key that is unlocked using a PIN or biometric. Authentication is based on proving possession of the protected key rather than sending a password to a server.

From a NIST perspective:

  • The TPM-protected device serves as something you have.

  • The PIN or biometric serves as something you know or something you are.

Together, these factors create a multi-factor authentication experience supported by cryptographic identity verification.

Why This Matters for CMMC and Microsoft 365 Security

For organizations pursuing CMMC compliance, protecting Controlled Unclassified Information (CUI), or strengthening Microsoft 365 security, understanding NIST's authentication guidance is critical.

Many organizations focus only on whether MFA is enabled. NIST's guidance encourages organizations to think beyond simple checkbox compliance and evaluate how authentication is being performed.

Hardware-backed, cryptographic authentication methods help reduce exposure to many of the threats identified within SP 800-63B and provide stronger protection against credential-based attacks.

Final Thoughts

NIST SP 800-63B does not define MFA as simply using a password plus a one-time passcode. Instead, it focuses on the assurance provided by authenticators and the factors used to protect them.

By recognizing TPM-protected cryptographic authenticators, NIST acknowledges that strong authentication can be achieved through hardware-backed credentials protected by a PIN or biometric factor. Understanding this distinction helps organizations make more informed decisions about authentication strategies, Microsoft 365 security, and compliance initiatives.

The takeaway is simple: modern authentication is no longer just about stronger passwords. It is about stronger credentials, stronger identity verification, and stronger protection against today's most common attack methods.

Previous
Previous

Compliance Is What You Prove. Security Is What You Live.

Next
Next

Configuring Windows Hello for Business Securely