Proof that the sender derived the same pairwise key, computed over this whole EAPOL frame with this field zeroed.
Zero in message 1, real in the other three. Computed with the key confirmation key — the first sixteen octets of the derived pairwise key — which is why validating it proves both sides agree on a secret neither ever transmitted.
EAPOL-Key > Key MIC