Yubico announced the expansion of its Enrolment services, available exclusively through YubiKey as a Service – to include support for simple and secure in-the-field enrollment of YubiKeys for Microsoft and PingID environments.
These expanded enrolment options help customers fast-track to phishing-resistance and passwordless, and more easily customise and secure their EntraID and PingOne PingID registration and account recovery experiences.
As part of expanding the scope of Enrolment services, Yubico is introducing a new Enrolment app: YubiKey as a Service – Enroll, currently in Limited Early Access for Android users.
With feedback from enterprise customers during this phase, the final offering will be available as both a standalone app and an SDK.
These capabilities will provide enterprises with the components required to build a custom experience for IT and HR teams for streamlined user onboarding.
“As cyber attacks become more sophisticated, organisations are increasingly seeking faster ways to eliminate passwords and protect users from phishing-based credential theft,” said Albert Biketi, chief product and technology officer at Yubico,”
“The expansion of YubiKey as a Service, with these new Enrolment service options, makes it easier for IT or business line managers to easily enrol and recover YubiKeys for their users,” said Biketi
“It also gives organisations the flexibility to integrate YubiKey deployment directly into their existing workflows, fast-tracking passwordless adoption and strengthening security across the enterprise.” he said.
Flexible Enrolment Options for Passwordless Deployment at Scale
Organisations will be able to choose the enrolment approach that best fits their deployment model and needs: a fully managed enrolment service with pre-configured YubiKeys, or an enrolment app or SDK, used onsite, that allows IT and non-technical staff to easily enrol YubiKeys on behalf of users.
- FIDO Pre-reg: A fully managed enrollment service
A turnkey service that delivers pre-enrolled YubiKeys directly to employees, enabling passwordless login from day one.
Keys are factory-programmed with user credentials and shipped globally, reducing operational overhead for IT teams.
FIDO Pre-reg is currently generally available with Okta and Versasec, and in Early Access with Microsoft.
- YubiKey as a Service – Enrol app and SDK: Instant registration or recovery for YubiKeys
Yubico’s enrollment service options also offer organisations a new, intuitive app called YubiKey as a Service – Enrol to quickly set up YubiKeys on behalf of users, such as new hires or existing employees.
With an accompanying SDK, organisations will be able to gain the tools to integrate user enrollment, registration and account recovery directly into their existing business applications.
Now IT teams, HR departments, and onboarding teams can securely prepare and assign YubiKeys on behalf of users, enabling seamless onboarding and rapid deployment of phishing-resistant authentication faster and at greater scale than ever before.
This service is now available in Limited Early Access for Microsoft and Ping Identity customers.
- YubiEnroll: Command-line tool to enrol YubiKeys
A free option that allows IT teams or partners to enrol YubiKeys on behalf of users and distribute them directly.
YubiEnroll is a command-line interface tool meant purely for technical teams to enrol YubiKeys on short notice or in regions where turnkey delivery services may not be available.
Key capabilities of the new Enrolment services include:
- Secure setup from anywhere: YubiKeys can be prepared and assigned without complex IT configuration, with secure backend provisioning handled by Yubico.
- End-to-end encrypted enrolment: All information used to configure keys is securely encrypted, protecting against interception or tampering.
- Flexible delivery options: Organisations can ship keys directly or leverage logistics partners and distributors for global fulfilment.
- Full visibility and auditing: Enrolment and activation events are automatically tracked to support compliance and operational oversight.
- Easy reassignment: Keys can be securely reset and reassigned when employees change roles or leave the organisation.
By combining flexible enrolment options with hardware-backed phishing resistance, YubiKey as a Service enables organisations to quickly deploy secure authentication across distributed workforces while maintaining strong governance and operational control.
Since 2007, Yubico has helped shape global authentication standards, co-created FIDO2, WebAuthn, and FIDO U2F, and introduced the original passkey.
Today, it’s passkey technology secures people and organisations in over 160 countries – transforming how digital identity is protected from onboarding to account recovery.
