YubiKey para empresas
Guides and Tutorials

YubiKey for Enterprises: How to Enable It in Google Workspace and Microsoft 365

Google Workspace and Microsoft 365 allow you to enforce the use of physical security keys as a second factor — but the configuration path, policy name, and license requirement differ on each platform. Here are the exact steps for both, with the differences that matter before rolling it out to your entire organization.


Google Workspace — Admin Console

1
Go to Security → Authentication → 2-step verification

From admin.google.com, with a super admin account: Menu → Security → Authentication → 2-step verification.

2
Enable "Allow users to turn on 2-Step Verification"

This is the base toggle. Without it, users cannot register any second factor, not even voluntarily.

3
Configure "Security key enforcement: Require security key"

This is the option that specifically enforces the use of a physical key, rather than leaving SMS or authenticator app as an alternative.

4
Apply it first to the administrators OU

Before rolling it out to the entire organization, test it with the administrators organizational unit (OU). This is the standard recommendation to avoid locking anyone out by mistake.

ℹ️ An important caveat

If you enable enforcement before the user has registered a key, they can be locked out of their account. Make sure each person has linked their YubiKey before enforcing the requirement, or give them a grace period for enrollment.


Microsoft 365 / Entra ID — Passkey (FIDO2)

Microsoft has renamed the "FIDO2 Security Key" policy to Passkey (FIDO2), and as of March 2026 introduced "Passkey Profiles" as standard configuration. Relevant fact: as of September 1, 2026, passkeys becomes the default authentication method in Entra for all tenants.

1
Go to Authentication methods → Policies

From the Microsoft Entra admin center, with Authentication Policy Administrator role: Authentication methods → Policies → Passkey (FIDO2).

2
Accept the migration to Passkey Profiles if you haven't already

If your tenant hasn't migrated, you'll see a prompt to opt into the new profiles. Once accepted, it cannot be reverted — your current settings are moved to a "Default" profile.

3
Configure the profile — Device-bound for physical keys

In the Configure tab, choose the passkey type: "Device-bound" covers physical YubiKeys. "Synced" is for passkeys in iCloud Keychain or Google Password Manager — they're not the same.

4
Assign the profile to a pilot group first

In Enable and Target, add a small group (for example, your IT team) before applying it to "All Users".

⚠️ The licensing nuance that gets overlooked

Registering and using a FIDO2 key is free in any edition of Entra ID, including the free one. But enforcing its use over weaker methods (like SMS) requires Conditional Access, which requires a P1 license — included in Microsoft 365 Business Premium, E3, or E5. Without that license, you can register the key but you cannot prevent a weaker method like SMS from being used as an alternative.


Google Workspace vs Microsoft 365 — key differences

Aspect Google Workspace Microsoft 365 / Entra ID
Policy name Security key enforcement Passkey (FIDO2)
Where to configure Admin console → Security → Authentication Entra admin center → Authentication methods → Policies
Cost to enforce exclusively Included in any Workspace plan Requires P1 license (Conditional Access)
Deployment recommendation Pilot in administrators OU Pilot in a small group before "All Users"

Before enforcing it across your organization

On both platforms, the most common mistake is enabling enforcement before everyone has a registered key. Always start with a pilot group, and make sure each person has a second backup key registered — if they lose the only one they have, they'll be locked out of their account.

For the full details on why it's a good idea to have a spare key and how to register it, check out the guide at Do I Need 2 YubiKeys? Complete Backup and Recovery Guide. And if you still need to convince your company to take this step before you get to the technical part, you'll find the arguments in YubiKey at Work: How to Convince Your Company to Use It.


Keys for your team — bulk ordering

To deploy YubiKey to a team, it's common to order multiple units at once, with a 2-slot tray so each person can carry their primary key and backup together.

Compatible NFC + USB-A YubiKey 5 NFC

YubiKey 5 NFC

The most widely deployed security key in corporate environments. Compatible with Google Workspace, Microsoft 365, SSH, and password managers. USB-A + NFC.

✅ Ideal for: standard team deployment
View on Amazon
Backup included YubiKey Card Tray 2 Slots

Card Format Tray — 2 Slots

Carry your primary key and backup together in credit card format. Made in Spain (EU). Fits in any wallet.

✅ Ideal for: primary key + backup per employee
View on Amazon

Frequently asked questions

Can I use the same YubiKey in Google Workspace and Microsoft 365 at the same time?

Yes. The same physical key can be registered as a second factor in multiple services simultaneously, including both platforms, without conflict between them.

Do I need Microsoft's P1 license just to register the key?

No. Registering and using Passkey (FIDO2) is free in all editions of Entra ID. The P1 license is only needed if you want to enforce its use over weaker methods via Conditional Access.

What happens to users who already had 2FA configured before enforcing the key?

In Google Workspace, if the user already has a second factor registered (such as a key or phone), they will be able to continue accessing with it when enforcement is enabled. In Microsoft 365, it's advisable to review the status of each passkey profile before applying the policy to everyone.

Verdict

Microsoft's licensing nuance is what surprises administrators the most

In Google Workspace, enforcing a security key has no additional cost. In Microsoft 365, you can register and use the key at no extra cost, but enforcing it exclusively over weaker methods requires a P1 license. Review this before planning your deployment, not after.

As an Amazon Associate, I earn from qualifying purchases.

Back to blog