Deploying YubiKey hardware security keys in an organization is one of the most effective measures a company can take to protect against phishing and account takeover. However, the decision to purchase keys is only the beginning — the success of a deployment depends on careful planning, proper integration with existing IT infrastructure, and preparing users for the change in how they authenticate. This guide presents a practical approach to deploying YubiKey keys with the FIDO2 protocol in a corporate environment, based on nFlo’s experience delivering these projects.
Why are passwords and SMS codes no longer enough?
The statistics speak for themselves: over 80% of data breaches start with compromised credentials. Traditional multi-factor authentication (MFA) methods such as SMS codes or authenticator apps generating one-time passwords (TOTP), while significantly improving security compared to passwords alone, are vulnerable to increasingly sophisticated attacks.
SMS codes can be intercepted through SIM swapping attacks, where a criminal transfers the victim’s phone number to their own SIM card. Authenticator app codes, while more secure, can be phished by advanced real-time proxy phishing sites that act as a Man-in-the-Middle between the user and the genuine service. Push notifications are vulnerable to MFA fatigue attacks, where the attacker bombards the user with approval requests until they eventually accept one.
YubiKey hardware security keys with the FIDO2/WebAuthn protocol eliminate these attack vectors entirely. The key cryptographically verifies the domain it is communicating with and will refuse to authenticate on a fraudulent site — regardless of how perfect the replica appears. This is known as origin binding, which makes phishing technically ineffective.
📚 Also read: YubiKey: What are they and why should you implement them in your company? — a comprehensive guide to YubiKey technology
How to plan a YubiKey deployment in your organization?
An effective hardware MFA deployment requires a systematic approach. Below we present a proven process that minimizes the risk of issues and ensures smooth user adoption.
Step 1: System inventory and readiness assessment
Before purchasing the first key, you need to conduct a thorough inventory of all systems requiring authentication in the organization. For each system, determine which authentication protocol is supported:
- FIDO2/WebAuthn — the preferred protocol for modern cloud applications (Microsoft 365, Google Workspace, AWS, Salesforce) and operating systems (Windows Hello for Business, macOS). Provides the highest level of security and enables passwordless login.
- FIDO U2F — an older but still secure standard, supported by most web services as a second authentication factor.
- PIV/Smart Card — essential for Windows login in Active Directory environments, VPN access, and for digital signing and email encryption (S/MIME).
- OTP (Yubico OTP, OATH-HOTP/TOTP) — a solution for legacy systems that do not support newer standards but require a second factor.
This inventory will help you select the right key models and identify any compatibility gaps that need to be resolved before the rollout begins.
Step 2: Selecting key models for different user groups
Yubico offers a wide range of models, and choosing the right key depends on the user profile and hardware in use:
- YubiKey 5 NFC (USB-A + NFC) — the most versatile model, ideal for employees using older laptops with USB-A ports and smartphones with NFC.
- YubiKey 5C NFC (USB-C + NFC) — the optimal choice for users of modern laptops and mobile devices with USB-C.
- YubiKey 5 Nano (USB-A) or YubiKey 5C Nano (USB-C) — miniature keys designed to remain semi-permanently in the USB port, convenient for fixed workstations but easier to lose.
- YubiKey 5Ci (USB-C + Lightning) — the only model supporting the Lightning connector, useful in organizations with a large number of older Apple devices.
The key principle: every employee should receive a minimum of two keys — one primary key for daily use and one backup stored securely (e.g., at home or in a company safe). Without a backup key, losing the only key results in access lockout and the need to initiate an emergency recovery procedure.
Step 3: Integration with your identity management platform
The central element of the deployment is integrating YubiKeys with your identity and access management (IAM) platform. The most common integration scenarios include:
Microsoft Entra ID (Azure AD): Entra ID natively supports FIDO2 keys as an authentication method. Configuration involves enabling the FIDO2 authentication method in the admin portal, defining Conditional Access policies that require hardware MFA for access to critical resources, and optionally restricting accepted keys to specific YubiKey models using Attestation UIDs (AAGUIDs).
Okta: Okta supports FIDO2/WebAuthn keys as an authentication factor within MFA policies. Administrators can enforce the use of hardware keys for specific user groups or applications and configure an enrollment flow that guides users through the key registration process.
Google Workspace: Google Workspace allows you to enforce security keys as the only second factor method, which is particularly important for phishing protection. Google’s Advanced Protection Program, based solely on hardware keys, eliminated account takeover incidents among Google’s 85,000 employees.
Step 4: Pilot with early adopter group
Before a full rollout, it is critical to run a pilot with a group of 10-30 users representing different roles and usage scenarios in the organization. The pilot group should include:
- IT and security administrators (users with the highest privileges)
- Members of senior management (frequently targeted by spear-phishing)
- Mobile workers (testing NFC on mobile devices)
- Users of legacy systems (verifying OTP/PIV compatibility)
During the pilot, monitor: key registration time, frequency of login issues, helpdesk tickets, and collect user feedback on convenience and clarity of instructions.
Step 5: Phased rollout and training
Based on findings from the pilot, proceed with a phased deployment to subsequent user groups. A proven approach is to roll out in waves of 50-100 users per week, allowing IT to manage the workload and respond quickly to any issues.
User training should cover:
- A hands-on demonstration of key registration in the main company systems
- Instructions on what to do if a key is lost or damaged
- An explanation of why the organization is deploying hardware MFA and the security benefits it provides
- Reference materials (a quick guide, FAQ, helpdesk contact details)
What security procedures accompany a YubiKey deployment?
Deploying hardware keys requires developing a set of key lifecycle management procedures that are just as important as the technical integration itself.
Key issuance and registration procedure
The key issuance process should include identity verification of the employee (preferably in person), signing a receipt confirmation for both the primary and backup key, registering both keys in all required systems in the user’s presence, and documenting the serial numbers of keys assigned to each employee.
Lost or damaged key procedure
When a YubiKey is lost, you must immediately deactivate the lost key across all registered systems, review authentication logs for any unauthorized use, and issue a new key and register it as a replacement. If the employee does not have access to their backup key, an emergency procedure with an alternative identity verification method (e.g., in-person verification at the IT department or a video call with ID document presentation) must be initiated.
Offboarding policy
When an employee leaves the organization, the procedure should include the physical return of all assigned YubiKeys, deactivation and removal of keys from all IAM systems, and a factory reset of the keys before reuse or destruction.
Common challenges and how to address them
Based on experience from many deployments, nFlo has identified the most common challenges organizations face when deploying hardware MFA:
User resistance: Some employees see carrying a physical key as an inconvenience. The solution is clear communication of the benefits (faster login than copying codes, protection of personal accounts), setting a good example through senior management, and choosing convenient form factors (e.g., key on a keychain).
Systems without FIDO2 support: Older internal applications may not support modern authentication standards. In such cases, you can use the OTP or PIV protocols supported by YubiKey, implement an SSO (Single Sign-On) solution as an intermediary layer, or plan to modernize those systems.
Remote users and BYOD: Employees using personal devices may encounter USB port compatibility issues. Keys with NFC solve this problem for smartphones, and models with dual connectors (e.g., USB-C + NFC) provide flexibility.
Scaling costs: In large organizations, the cost of purchasing two keys per employee can be significant (100-200 USD per person). However, this cost should be weighed against the average cost of a security incident resulting from account takeover, which often reaches hundreds of thousands of euros.
How to measure the effectiveness of a YubiKey deployment?
After deploying hardware keys, it is worth monitoring key metrics that allow you to assess return on investment:
- Number of phishing incidents — an expected drop to zero for users with FIDO2 keys
- Password-related helpdesk tickets — an expected reduction of 50-80% when transitioning to a passwordless model
- Login time — YubiKey authentication is on average 4x faster than entering a code from an authenticator app
- Adoption rate — target: 95%+ employees with registered keys within 3 months of rollout start
- Key loss rate — typically 2-5% annually, which should be factored into the budget for replacement keys
Regulatory compliance: how YubiKey helps meet NIS2, DORA, and PCI DSS requirements
A FIDO2-based hardware MFA deployment directly supports compliance with key regulations:
- NIS2 — the directive requires the use of multi-factor or continuous authentication for access to network and information systems. FIDO2 keys meet this requirement at the highest security level.
- DORA — the regulation requires financial entities to implement strong authentication mechanisms. YubiKey with FIDO2 is considered the gold standard in this area.
- PCI DSS v4.0 — the new version of the standard requires phishing-resistant MFA for access to cardholder data environments. FIDO2 hardware keys natively meet this requirement.
- ISO 27001 — control A.8.5 (Secure Authentication) is fully addressed by deploying hardware keys as a strong second factor.
Key takeaways: deploying YubiKey in your company
- Planning is essential — system inventory, key model selection, and IAM integration must precede the rollout.
- Two keys per employee — a primary and backup key is the absolute minimum to avoid access lockouts.
- Pilot before rollout — testing with a group of 10-30 users allows you to identify issues before deploying across the entire organization.
- Management procedures — issuance, loss, offboarding — every scenario must have a defined procedure.
- Training and communication — deployment success depends on end-user understanding and acceptance.
Need support deploying YubiKey keys in your organization? nFlo experts will help you plan and execute the entire process — from needs analysis, through integration with your systems, to user training.
What a hardware MFA rollout costs beyond the keys
The keys are the cheap part. What decides whether a rollout succeeds is everything around them: a second registered factor for every user so a lost key does not become a helpdesk outage, a documented recovery path that cannot itself be phished, and an inventory of the applications that will keep accepting a weaker factor after the project is declared finished. Skipping the third turns strong authentication into an expensive front door next to an open window.
Planning that sequence — pilot group, recovery model, application coverage — is the substance of an MFA deployment.
Related Terms
Learn key terms related to this article in our cybersecurity glossary:
- Authentication — Authentication is the process of verifying the identity of a user, device, or system…
- FIDO2 — FIDO2 is an open authentication standard developed by the FIDO Alliance…
- Phishing — Phishing is a type of social engineering attack that aims to deceive the victim and…
- Identity and Access Management — Identity and Access Management (IAM) is a framework of policies and technologies…
- Single Sign-On — Single Sign-On (SSO) is an authentication mechanism that allows a user to…
Learn More
Explore related articles in our knowledge base:
- YubiKey: What are they and why should you implement them in your company?
- Two-Factor Authentication (2FA) - Why Use It and How to Implement
- What is MFA - Multi-Factor Authentication?
- What is FIDO2 authentication?
- Identity and Access Management (IAM) - from basics to Zero Trust
Explore Our Services
Need cybersecurity support? Check out:
- Security Audits - comprehensive security assessment
- Penetration Testing - identify vulnerabilities in your infrastructure
- SOC as a Service - 24/7 security monitoring
