What is Yubikey?

A Yubikey is a physical authentication device manufactured by Yubico that plugs into a computer or mobile device to provide strong two-factor authentication (2FA) and passwordless login capabilities. It functions as a hardware security key that generates cryptographic codes to verify user identity, eliminating reliance on passwords alone and significantly reducing the risk of phishing, credential theft, and unauthorized access.

The device works by supporting multiple authentication protocols including FIDO U2F, FIDO2, smart card (PIV), and one-time passwords (OTP). For example, when an HR manager logs into a cloud-based HRIS system, they insert their Yubikey 5 NFC into a USB port or tap it against their phone, press the button, and the device communicates directly with the service to confirm their identity. This hardware-based approach ensures that even if passwords are compromised, accounts remain protected because the physical key is required for access.

Why Yubikey Matters

Yubikeys matter in HR operations because they protect sensitive employee data, payroll systems, and recruitment platforms from increasingly sophisticated cyber threats. With HR departments managing confidential personal information, compensation details, and compliance records, a single security breach can result in regulatory penalties, reputational damage, and loss of employee trust. Hardware security keys provide phishing-resistant authentication that software-based methods cannot match, ensuring that only authorized personnel access critical HR systems regardless of password compromises or social engineering attacks.

How to Use Yubikey at Work

  1. Assess system compatibility: Verify that your HR software, applicant tracking systems, and cloud platforms support FIDO U2F security key or FIDO2 protocols. Most modern platforms including Google Workspace, Microsoft 365, and major HRIS systems offer Yubikey integration.
  2. Procure and distribute keys: Purchase Yubikeys appropriate for your team's devicesβ€”Yubikey 5 NFC models work with both USB and mobile devices. Assign keys to HR staff who access sensitive systems and maintain a secure backup key inventory.
  3. Enroll keys in systems: Guide users through the enrollment process for each platform, which typically involves inserting the key, navigating to security settings, and registering the device as a second authentication factor.
  4. Establish protocols: Create policies for key storage, loss reporting, and backup authentication methods. Train HR staff on proper usage and maintain documentation for onboarding new team members.
πŸ’‘
Intervue Pro Tip

Stop pulling engineers into interviews. Intervue's Interview as a Service platform puts 2,500+ vetted experts from FAANG and top tech companies on your hiring panel, delivering detailed candidate reports in under 40 minutes. Your team focuses on building. See how it works β†’

‍
‍

Key Statistics & Benchmarks

πŸ“Š
Benchmark Data
  • 99.9% phishing resistance β€” Hardware keys block credential phishing attacks that bypass SMS and app-based 2FA.
  • Supports 5+ protocols β€” Yubikeys work with FIDO U2F, FIDO2, OTP, smart card, and OpenPGP authentication standards.
  • 10+ year lifespan β€” Yubikeys require no batteries or charging, functioning reliably for a decade or more with proper care.
  • Works across 1000+ services β€” Compatible with major platforms including Google, Microsoft, Salesforce, and most enterprise HR systems.

Common Mistakes to Avoid

⚠️
Watch Out For
  • Not maintaining backup keys: Always register a backup Yubikey and store it securely to prevent lockouts if the primary key is lost.
  • Skipping mobile compatibility: Choose NFC-enabled models like Yubikey 5 NFC to ensure functionality across both desktop and mobile HR applications.
  • Inadequate loss protocols: Establish immediate deactivation procedures for lost keys to prevent unauthorized access before replacement keys are issued.

Frequently Asked Questions

Common questions about Yubikey answered by the Intervue HR team.

What is a Yubikey and how does it work?

A Yubikey is a hardware authentication device that plugs into your computer or taps against your phone to verify your identity. When logging into a protected system, you insert the key and press its button, which generates a cryptographic response that proves you possess the physical device. This creates phishing-resistant two-factor authentication that protects accounts even if passwords are stolen.

How do I set up a Yubikey for my HR systems?

To set up a Yubikey, first verify your HR platform supports FIDO security keys. Log into your system's security settings, select "Add security key" or "Two-factor authentication," then insert your Yubikey when prompted and press the button. The system will register the device. Repeat this process for each platform you access, and always register a backup key in case your primary is lost.

What is the difference between Yubikey 5 NFC and other security keys?

The Yubikey 5 NFC offers both USB connectivity and Near Field Communication (NFC) capability, making it compatible with computers, smartphones, and tablets. Other FIDO U2F security keys may only support USB or lack support for multiple authentication protocols. The Yubikey 5 series supports FIDO2, U2F, smart card, and OTP protocols, providing broader compatibility across enterprise systems compared to basic security keys.

Can multiple employees share a single Yubikey?

No, Yubikeys should never be shared between employees. Each key should be assigned to a single individual and registered to their specific accounts to maintain accountability and security. Sharing keys defeats the purpose of authentication by making it impossible to verify who actually accessed a system. Organizations should purchase individual keys for each HR team member who requires access to sensitive systems.