Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A YubiKey can protect Microsoft accounts, Microsoft Entra work accounts, supported websites, authenticator codes, and certificates. Windows 11 lock-screen sign-in is a separate, organization-managed feature: plugging in a YubiKey does not automatically make it a Windows login key.

Use Yubico Authenticator for graphical management and YubiKey Manager CLI (ykman) for command-line administration. YubiKey Manager GUI reached end of life on February 19, 2026 and is no longer supported.

Which YubiKey function should you use?

YubiKeys contain independent applications, and your model determines which applications are available.

Function Purpose Typical Windows 11 use
FIDO2/passkeys Phishing-resistant authentication using a PIN, fingerprint on supported keys, and/or touch Microsoft, Google, GitHub, password managers, and supported websites
FIDO U2F Older security-key standard Legacy services that do not support full FIDO2 passkeys
OATH-TOTP/HOTP Generates time-based or counter-based one-time codes Used like an authenticator-app code
Yubico OTP Types a Yubico-specific one-time password as keyboard input Only services that specifically support Yubico OTP
PIV Stores certificates and private keys Smart-card logon, certificate authentication, signing, and encryption
OpenPGP Stores OpenPGP keys Email and file encryption or signing

The Security Key Series supports FIDO2 and FIDO U2F, but not PIV, OATH, or Yubico OTP. A YubiKey 5 Series generally offers a broader set of applications. Check the exact model before buying one for a particular job.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Install the current Windows 11 software

Install Yubico Authenticator

Yubico Authenticator supports Windows 10 and later; x64 is the fully supported Windows platform. Install it from the Microsoft Store or download Yubico’s Windows MSI installer.

  1. Download the current Windows installer from Yubico Authenticator.
  2. Double-click yubico-authenticator-<version>-win64.msi.
  3. Follow the installation prompts. Local Group Policy may require administrator permission.
  4. Insert your YubiKey and open Yubico Authenticator.

The menus depend on the key model and enabled applications. They can include FIDO2 passkey and PIN management, fingerprints on supported Bio keys, OATH accounts, PIV certificates, and supported OTP slots.

Install YubiKey Manager CLI

The current command-line tool is ykman. Choose the Windows installer whose filename does not contain -qt; installers containing -qt belong to the discontinued GUI line.

Open Command Prompt or PowerShell as administrator, then verify the installation:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Run where ykman.
  2. Run ykman -v.
  3. Run ykman info.

If Windows cannot find the command, run the executable directly from a typical installation location:

  • C:\Program Files\Yubico\YubiKey Manager CLI\ykman.exe
  • C:\Program Files (x86)\Yubico\YubiKey Manager CLI\ykman.exe

Yubico documents FIDO commands that begin with ykman fido as requiring an elevated Command Prompt or PowerShell session on Windows.

Inspect the YubiKey before changing anything

Insert the key and run ykman info. It reports the model, serial number, firmware, enabled USB interfaces, and available applications.

To list connected keys, run ykman list. To output only serial numbers, run ykman list –serials.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Do not assume two YubiKeys have the same capabilities. The model, firmware, enabled interfaces, and connection method—USB or NFC—can affect which operations are available.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Set up a YubiKey for a personal Microsoft account

A FIDO2-capable key can be registered as a passkey for a Microsoft personal account.

  1. Open account.live.com/proofs/manage and sign in.
  2. Select Add a new way to sign in or verify.
  3. Choose Face, Fingerprint, PIN, or Security Key.
  4. When prompted for a save location, choose Security key or Save another way, then select the physical key.
  5. Insert the YubiKey, or tap an NFC-capable key to an NFC reader.
  6. Create or enter the YubiKey’s FIDO2 PIN.
  7. Touch the key when prompted and give it a recognizable name.

To sign in later, enter your Microsoft account name, choose Sign-in options or Use Windows Hello or security key instead, then select the security-key option. Enter the FIDO2 PIN and touch the key if prompted.

Registering a YubiKey with a personal Microsoft account protects web authentication. It does not add a YubiKey credential to the Windows lock screen for a local Windows account.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Set up a YubiKey for a work or school account

For a Microsoft Entra work or school account, use the organization’s Security info page:

  1. Open mysignins.microsoft.com/security-info and sign in.
  2. Select Add sign-in method or Add method.
  3. Choose Passkey, then select Add if prompted.
  4. Choose the physical security-key option and select Next.
  5. Insert the YubiKey or tap it to an NFC reader.
  6. If the browser selects Windows Hello, a phone, or a password-manager passkey, choose More choices → Security key → Next.
  7. Enter the YubiKey FIDO2 PIN and touch the key.
  8. Name the key and select Next.

Labels and steps can vary with the browser and the organization’s Entra policy. On Windows 11 version 23H2 and later, More choices → Security key is a useful path when Chrome or Edge initially selects another passkey provider.

Use the YubiKey on supported websites

The website must support FIDO2, WebAuthn, or passkeys. A typical setup is:

  1. Open the website’s account-security or multifactor-authentication settings.
  2. Choose Add passkey, Add security key, or Security key.
  3. Select the physical security-key option rather than Windows Hello or a password manager.
  4. Insert or tap the YubiKey.
  5. Enter the FIDO2 PIN if requested.
  6. Touch the key and name the credential if asked.

A site that supports only authenticator-app TOTP cannot use a FIDO2 YubiKey unless it also offers a security-key method. A passkey is scoped to the website that created it and cannot authenticate to an unrelated service.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use a YubiKey to sign in to Windows 11

Native FIDO2 security-key sign-in at the Windows lock screen is an organizational Microsoft Entra feature. It requires a Microsoft Entra joined or hybrid joined device, a compatible FIDO2 key, an enabled Entra authentication-method policy, and additional organization configuration.

Microsoft documents minimums of Windows 10 version 1909 or later for Entra-joined devices, Windows 10 version 2004 or later for hybrid-joined devices, and Windows 10 version 1903 or later for WebAuthn. These minimums cover Windows 11 as well.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

This feature is not a general replacement for a local Windows account password or PIN, Windows Hello for Business, PIV smart-card logon, or a personal Microsoft account’s web security-key registration. An unmanaged Windows 11 Home or Pro PC does not gain FIDO2 lock-screen sign-in simply by installing Yubico Authenticator.

Configure it through Microsoft Intune

In the Microsoft Intune admin center, open Devices → Enroll Devices → Windows enrollment → Windows Hello for Business and set Use security keys for sign-in to Enabled.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For a targeted custom profile:

  1. Go to Devices → Windows → Configuration profiles → Create profile.
  2. Choose Windows 10 and later as the platform.
  3. Choose Templates → Custom.
  4. Name the profile, for example, Security Keys for Windows Sign-In.
  5. Add the OMA-URI ./Device/Vendor/MSFT/PassportForWork/SecurityKey/UseSecurityKeyForSignin.
  6. Set the data type to Integer and the value to 1.

For Microsoft Entra hybrid-joined devices managed with Group Policy, enable Computer Configuration → Administrative Templates → System → Logon → Turn on security key sign-in.

Sign in after enrollment

  1. At the Windows 11 sign-in screen, select Sign-in options.
  2. Select the security-key credential provider.
  3. Insert the YubiKey.
  4. Enter the FIDO2 PIN.
  5. Touch the key.

To manage the key after enrollment, open Settings → Accounts → Sign-in options → Security Key → Manage. Available actions can include changing the PIN, managing fingerprints on supported Bio keys, and resetting the key.

Set or change the FIDO2 PIN

Using Yubico Authenticator

  1. Insert the YubiKey and open Yubico Authenticator.
  2. Open the left navigation menu and select Passkeys.
  3. Under Manage, select Set PIN if no PIN exists, or Change PIN for an existing PIN.
  4. Enter the requested values and select Save.

Using ykman

  1. Run ykman fido info to display FIDO2 status.
  2. Run ykman fido access change-pin to change the PIN interactively.
  3. Run ykman fido credentials list to list discoverable credentials stored on the key.

Use interactive PIN entry where possible. Putting a PIN directly in a command can expose it through shell history or process inspection.

Yubico documents a normal FIDO2 PIN minimum of four characters, but requirements can be stricter for some models, firmware versions, FIPS configurations, or complexity policies.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

FIDO2 lockouts, resets, and passkey deletion

The FIDO2 PIN has a finite retry count. After three incorrect attempts in a row, remove and reinsert the key before trying again. After eight incorrect attempts, the FIDO2 application becomes blocked. A forgotten PIN cannot be recovered.

Resetting FIDO2 is destructive. Run ykman fido reset to remove FIDO2 and FIDO U2F credentials and return the FIDO application to its no-PIN state. This does not reset OATH, PIV, or other applications. Register a backup key with every important account before resetting.

In Yubico Authenticator, open Passkeys, unlock with the FIDO2 PIN, select a listed credential, and use its delete action. The list contains discoverable, resident credentials only; non-discoverable credentials may exist on the key without appearing there.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

If an account provider has deleted a credential but it remains on the YubiKey, remove the orphaned passkey in Yubico Authenticator or with ykman fido credentials delete <credential_id>, then register the key again.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use the YubiKey for authenticator-app codes with OATH-TOTP

OATH-TOTP is different from FIDO2. It generates a numeric code that you copy into a login form.

  1. Insert the key and open Yubico Authenticator.
  2. Open the left menu and select Accounts → Add account.
  3. Display the service’s authenticator-app QR code.
  4. Select Scan QR code, or choose manual entry.
  5. For manual entry, enter the issuer, account name, secret key, OTP type, algorithm, period, and code length exactly as supplied by the service.
  6. Optionally enable Require touch, then select Save.

To generate a code, open Accounts, unlock the OATH application if it has a password, select the account, and copy the displayed code into the website. Pinned accounts can also be accessed from the Windows system tray.

If a valid TOTP code is rejected, check that the computer’s clock is synchronized. A forgotten OATH password cannot be recovered; resetting OATH deletes all OATH accounts on the key. HOTP accounts can become unsynchronized because the counter advances whenever a code is generated.

Use Yubico OTP

Yubico OTP is a separate, older mechanism that types an OTP into the focused text field. It works only with services that specifically support Yubico OTP; it is not interchangeable with FIDO2 or a six-digit TOTP code.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Place the cursor in the service’s Yubico OTP field.
  2. Briefly touch the key for the short-press slot, or hold it for the long-press slot.
  3. Let the key type the OTP.
  4. Select Submit if the configured slot does not press Enter automatically.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Configure PIV smart-card features

PIV is intended for certificate-based authentication, signing, encryption, and smart-card logon. It is not the normal method for registering a consumer passkey.

To import a certificate:

  1. Insert the key and open Yubico Authenticator.
  2. Select Certificates from the left menu.
  3. Select a PIV slot and choose Import file under Actions.
  4. Enter the PIV management key when prompted.
  5. Select the certificate file and complete the import.
PIV slot Common purpose
9A Authentication
9C Digital signature
9D Key management and decryption
9E Card authentication

For many YubiKey 5 PIV applications, factory defaults are:

  • PIV PIN: 123456
  • PIV PUK: 12345678
  • Management key: 010203040506070801020304050607080102030405060708

Change all three before using PIV. PIV PIN and PUK retry limits are normally three attempts, although the YubiKey Bio Multi-protocol Edition has a default PIN retry count of eight and does not have a PUK. Resetting PIV deletes its private keys and certificates.

To check whether Windows detects the key as a smart card, run certutil -scinfo and certutil -key -csp "Microsoft Base Smart Card Crypto Provider".

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified (Pack of 2)
  • The information below is per-pack only
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.

Domain smart-card logon also requires a certificate authority, a suitable certificate template, trust configuration, Group Policy, and account mapping. Installing Yubico Authenticator alone does not create that environment.

Back up your authentication properly

FIDO2 private keys cannot normally be cloned from one YubiKey to another. Register a second key separately with each important service, store it securely, and test it before you need it.

OATH-TOTP is different: a second key can be configured with the same secret or QR code and will generate the same codes. HOTP backups require care because generating codes advances a counter.

Common mistakes to avoid

  • Using the old GUI: YubiKey Manager GUI is no longer supported; use Yubico Authenticator and ykman.
  • Buying the wrong model: Security Key Series models do not provide OATH or PIV.
  • Confusing protocols: FIDO2, OATH-TOTP, Yubico OTP, and PIV solve different problems.
  • Expecting personal-account registration to enable lock-screen login: Windows FIDO2 sign-in requires Microsoft Entra join or hybrid join and administrator policy.
  • Resetting without a backup: FIDO2, OATH, and PIV resets destroy credentials in their respective applications.
  • Choosing the wrong browser credential: select More choices → Security key when Windows Hello, a phone, or a password manager is selected instead.

FAQ

Can any YubiKey be used with Windows 11?

No. The key must support the function you need. Security Key Series models support FIDO2 and FIDO U2F, while YubiKey 5 models generally add OATH, PIV, and Yubico OTP.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Does a YubiKey replace my Windows 11 PIN?

Not automatically. Personal Microsoft-account registration is mainly for web authentication. Native FIDO2 lock-screen sign-in requires a Microsoft Entra joined or hybrid-joined device and administrator configuration.

What happens if I forget the FIDO2 PIN?

It cannot be recovered. You must reset the FIDO2 application, which deletes its FIDO2 and U2F credentials. Register a backup key before doing this.

Can I copy passkeys from my main YubiKey to a backup?

No. FIDO2 private keys are not normally exportable or clonable. Register the backup YubiKey separately with each account.

Why does my YubiKey not appear in the passkey list?

Yubico Authenticator lists discoverable resident credentials. A non-discoverable FIDO2 credential can be present and usable without appearing in that list.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Can a YubiKey generate Microsoft Authenticator-style codes?

A compatible YubiKey 5 can store OATH-TOTP accounts and generate numeric codes through Yubico Authenticator. This is separate from FIDO2 and requires the service’s TOTP secret or QR code.

How do I know whether my YubiKey supports PIV?

Run ykman info and check the available applications. Security Key Series models do not include PIV; many YubiKey 5 models do.

The Bottom Line

For most Windows 11 users, install Yubico Authenticator, inspect the key with ykman info, and register a FIDO2-capable YubiKey as a passkey with Microsoft and other supported services. Set a strong FIDO2 PIN, touch the key when prompted, and register a second key as a backup.

Do not confuse web passkeys with Windows lock-screen sign-in. The latter is an administrator-managed Microsoft Entra feature. OATH codes, Yubico OTP, and PIV are separate applications with separate setup and reset procedures.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.