This objective requires your organization to identify which types of accounts must use replay-resistant authentication methods—methods that prevent attackers from reusing captured credentials to gain unauthorized access. This is a foundational step before enforcing technical controls.