Phishing-resistant authentication across the Microsoft ecosystem
Adopting secure authentication and creating phishing-resistant users across your Microsoft ecosystem are crucial steps towards cyber resilience.
Stop phishing with a scalable user friendly
authentication solution
Microsoft’s MFA mandate and Secure Future Initiative have made phishing‑resistant authentication a requirement for every organization. YubiKeys deliver the fastest, most scalable path to compliance across Microsoft 365, Entra ID, Windows, Surface and Windows 365 Link PCs, and AI‑powered experiences like Copilot — without slowing down your users.
Why YubiKeys: The Gold Standard for Microsoft Environments
Purpose‑built for Microsoft identity
- Works across Microsoft 365, Entra ID, Windows, Surface and Windows 365 Link PCs, and AI‑powered experiences like Copilot
- Supports FIDO2, passkeys, smart card replacement, and mobile CBA
- FIPS‑validated options for regulated industries and government

Enterprise‑grade security
- Hardware‑rooted authentication resistant to phishing, man‑in‑the‑middle, and MFA fatigue
- No shared secrets, no SMS, no push notifications
- Offline‑capable and tamper‑resistant
User experience that scales
- Fast, consistent login across devices
- No batteries, no connectivity, no mobile dependency
- Works for frontline, hybrid, and high‑risk users
Securing the Digital Future Together: Microsoft and Yubico
For the last decade, Microsoft and Yubico have partnered to enhance security and user experience, ensuring seamless and secure access. But don’t take our word for it. Hear from Microsoft about what value this partnership brings to our mutual customers.
Simplify adoption of passwordless, phishing-resistant authentication with YubiKey as a Service – turnkey enrollment and delivery for global deployment
Yubico offers YubiKey as a Service, a flexible and cost effective way for smart enterprises and governments to adopt modern cybersecurity at scale and protect their entire ecosystem including the workforce, supply chain and end customers. YubiKey as a Service customers exclusively can benefit from Enrollment and Delivery services expediting their time to value for phishing-resistant authentication.
Think beyond phishing-resistant MFA, and fast-track the creation of phishing-resistant users. Through Enrollment services, enroll YubiKeys on behalf of users for fast user onboarding and adoption leveraging either FIDO Pre-reg or YubiEnroll.

Phishing-resistant MFA solutions for the win
Accelerate your Zero Trust journey with Microsoft and Yubico. Use our phishing- resistant passwordless MFA solution to secure your on-premise and cloud resources.
Securing modern enterprises with passwordless authentication
Increase efficiency in your organization and authenticate in seconds. The Surface Pro for Business is equipped with a built-in NFC reader to login passwordlessly with a FIDO2 passkey using the YubiKey 5 NFC or YubiKey 5C NFC.
Simple and secure sign on with certificate-based authentication
Microsoft Entra ID and YubiKeys secure enterprises, small businesses, federal agencies and consumers with phishing-resistant MFA with simple and secure sign in on laptops and mobile phones. YubiKey is currently the only external device that supports CBA on Android and iOS. Plus, the YubiKey is the only FIPS certified phishing-resistant solution available for Entra ID on mobile.
Safeguard your Microsoft ecosystem with a Zero Trust strategy
Learn why there is a critical need for phishing-resistant MFA to support Zero Trust for Microsoft environments. As organizations mature their digital capabilities leveraging Microsoft’s cloud solutions, it becomes increasingly important to adopt security frameworks such as Zero Trust to better protect people, devices, applications and data in the workplace and along the supply chain.

Let us help you create a custom plan for your business!
Phishing-resistant solutions with
Entra ID and YubiKeys
Organizations that deploy Entra ID can meet Microsoft’s MFA mandate requiring MFA for authentication into Azure and Entra ID environments while defending against phishing attacks in Azure, Microsoft 365, and remote desktop environments. Download our solution brief on how Yubico can help your organization meet Microsoft’s MFA mandate.

Certificate-based authentication (CBA)
CBA allows organizations to use YubiKeys as smart cards with Entra ID, eliminating the need for on-premises authentication solutions like ADFS, while supporting Zero Trust and cloud strategies.

Conditional Access authentication strengths: enforced FIDO or CBA policies
Combat phishing and eliminate an attack vector while protecting privileged users and critical assets by configuring Entra ID to require YubiKeys for phishing-resistant MFA (FIDO2/WebAuthn) or CBA.

Entra ID Virtual Desktop (EVD) supports FIDO and certificates
When paired with FIDO-based passwordless authentication that allows users to sign in their Entra ID credentials and YubiKeys, EVD allows users to connect to a cloud workstation with consistent security.

Entra ID CBA for Android and iOS mobile devices
CBA on mobile offers the same smart card authentication as desktops. YubiKey is the only device supporting CBA on Android and iOS, and the only FIPS certified phishing-resistant solution for Entra ID on mobile. With Executive Order 14028, the adoption of CBA and other phishing-resistant MFA are mandated.
Microsoft and YubiKey work seamlessly together
Video “How to” Instructional Series

Securely log in to Surface Pro 10 with YubiKey

YubiKey CBA – iOS for Apple Mail

YubiKey Entra ID CBA – Windows 11 Desktop login

Entra ID Certificate-based authentication on iOS devices

Entra ID Certificate-based authentication on Android Devices

New tools toYubiKey Entra ID FIDO2 – Windows 11 Desktop login prevent phishing with Azure AD and YubiKeys
“Our team uses mobile phones, tablets, and other devices. Through Yubico, I need to partner indirectly with Microsoft to understand what they have, what they offer, and how it works with the YubiKey. The YubiKey works to replace one-time passwords, it works as multi-factor authentication, it factors all that into one easy to-use device. I was able to implement it with my forward thinking methods. I feel like it’s put me in the top 1% of public sector for implementing this using certificate-based authentication that Microsoft provides. I am freed up to focus on servicing the people in my city.”
Securing organizations around the world
Phishing-resistant MFA solutions for the win
“Our mission is our citizens. It’s our responsibility to build a fortress wall between threat actors and citizen data with enhanced methods of multi-factor authentication.”
Hyatt Hotels is going passwordless
“Our goal at Hyatt is to have every application in our stack fall under Azure single sign on. So once you’re using the YubiKey for app one, you’ll be using it for app two and three and four…”
The Government of Nunavut turns to phishing-resistant YubiKeys
“The initial rollout has been quite seamless and we have been able to quickly onboard our users. With a strong infrastructure in place and easy access to documentation and support, we are confident that we have taken back security and control.”
Microsoft and Yubico provide secure
authentication solutions
Featured content

How to get started with phishing-resistant MFA for your Microsoft environment

Protect your ecosystem with Yubico’s scalable phishing-resistant authentication

Strengthen cyber resilience in your Microsoft ecosystem with phishing-resistant MFA

Accelerate your Zero Trust journey with the top five use cases for Microsoft

Meet the Microsoft MFA Mandate with YubiKeys
Get started

Find the right YubiKey
Contact our sales team for a personalized assessment of your organization’s needs.
