Review of Yubico YubiKeys as an MFA Solution
February 02, 2024

Review of Yubico YubiKeys as an MFA Solution

Justin Ruddy | TrustRadius Reviewer
Score 10 out of 10
Vetted Review
Verified User

Modules Used

  • YubiKey 5 FIPS Series

Overall Satisfaction with Yubico YubiKeys

We initially implemented Yubico YubiKeys as a replacement to our OTP token-based MFA solution, due to the old solution no longer satisfying our security requirements. We started by using them in the role of PIV/CAC for cert-based authentication but soon expanded to using them as FIDO2 devices for other systems. The flexibility and ease with which we were able to deploy this highly secure 2-factor solution are highlights of the product for us.
  • Certificate-based authentication, in PIV/CAC smart card role
  • FIDO2 device, used with 3rd party systems which are difficult to implement cert-based authentication on
  • Reliable, long-lasting hardware token, with no batteries to replace, perpetual licensing, and simple management.
  • Looking forward to pre-provisioning, especially with Okta
  • Some type of centralized management system, some way to automate inventory management and tracking, at least at the moment of deployment
  • Regulatory compliance
  • Ease of use
  • Security
  • Has expanded the scope of systems we were able to secure via MFA
  • Has allowed additional 2-factor authentication methods to be considered for some systems
  • Has allowed for creative answers to MFA requirements
Significantly reduced our risk exposure, by expanding the number of systems we are able to provide MFA authentication on. It has also provided a great alternative authentication method when users lose their primary authenticator (smart card).
We initially implemented Yubico YubiKeys as a replacement to our OTP MFA solution, due to the old solution no longer satisfying our security requirements. We started by using them in the smart card role for cert-based authentication, but our users were so positive when we rolled them out, that we soon expanded to using them as FIDO2 devices for other systems. Users are pushing us to expand the number of systems that are Yubico YubiKey-enabled.
Broader adoption and support, more product options, and better compliance with standards and regulations.

Do you think Yubico YubiKeys delivers good value for the price?

Yes

Are you happy with Yubico YubiKeys's feature set?

Yes

Did Yubico YubiKeys live up to sales and marketing promises?

Yes

Did implementation of Yubico YubiKeys go as expected?

Yes

Would you buy Yubico YubiKeys again?

Yes

Yubico YubiKeys shines when used as part of a larger MFA solution. It provides a very flexible component, however, it remains dependent on the infrastructure and environment in which it is deployed.