Here’s what you need to do to set up a USB security key on Windows 11.
- Go to Settings > Accounts > Sign-in options.
- Under Ways to sign in, go to Security key and click Manage.
- After you click Manage, a window will pop up prompting you to insert your USB security key.
- Insert your USB security key or tap your NFC reader to verify your identity on your Windows 11 PC now.
- Once your physical security key is connected, you can either change the Security Key PIN or Reset Security Key back to factory settings.
- Click Close when you are finished.
Last updated September 2026 for Windows 11 25H2, YubiKey 5.8 firmware, and the latest FIDO2/WebAuthn passkey guidance.
A physical USB security key plugs into your computer’s USB port and functions as an extra layer of protection that’s used on Windows 11 and your Microsoft Account.
When you use Windows Hello as a sign in authentication method, you typically think about providing your face or your fingerprint for verification. But you could also use a FIDO2-compliant USB physical security key.
You can use a USB security key with a unique PIN as a passwordless sign-in method to sign into Windows 11 and access your Microsoft account.
Because security keys require you to have the physical device and something that only you know, like a unique PIN, physical security keys are considered to be a stronger authentication method than using just a username and password.
What’s new for security keys in 2026
A lot has moved in a year. On Windows 11 25H2 (build 26200.x), the Sign-in options page has stayed put, but the ecosystem around it has changed significantly:
- YubiKey 5.8 firmware is now the default across the YubiKey 5 Series, Security Key Series, and Bio Series. It adds CTAP 2.3, WebAuthn extensions in developer preview, support for up to 16 relying party IDs, and Persistent PIN User Access Token (PPUAT) for smoother sign-in flows. The FIPS variant stays on 5.7.4 to retain FIPS 140-3 validation.
- Storage for 100 device-bound passkeys per key (up from 25), 64 OATH seeds, 24 PIV certificates, and 2 OTP seeds — a total of 190 credentials per YubiKey.
- Passkeys have become the default sign-in prompt for Microsoft, Google, and Apple accounts in 2026. Physical keys still slot right in — you register them the same way, and Microsoft treats them as the highest-assurance authenticator.
- Enterprise attestation is now widely used in Entra ID, so IT can confirm the specific security key model a user registered.
Set up a USB security key on Windows 11
Of course, you can’t simply create a USB physical security key by just using any spare USB flash drive like you can create a USB startup key. Instead, you need to buy a FIDO2 security key.
According to Microsoft, a FIDO2 security key is “an unphishable standards-based passwordless authentication method.” FIDO2 security keys are typically USB devices that are equipped with Bluetooth or NFC.
Since a FIDO2 USB security key is equipped with the hardware to handle the authentication, the security of the account is increased because there’s no password that could be exposed or guessed. FIDO2 security keys are a great option for enterprises who are very security sensitive and can also be used for employees who aren’t willing or able to use their phone as a second factor for authentication.
I bought the Security Key NFC by Yubico because I didn’t want to spend a lot and other YubiKey options seemed to have more features than I needed. In 2026 that same key ships with 5.8 firmware and now stores 100 passkeys instead of 25 — a huge upgrade for anyone with more than a handful of FIDO2-enabled accounts.
The Security Key NFC by Yubico is around $29 in 2026, supports FIDO2 (Fast IDentification Online) and U2F (Universal 2nd Factor), and has a USB-A connection with NFC connectivity. It’s also IP68 rated and made of ceramic, so I can carry it on my keychain without having to worry about getting it wet or damaged.
💡 Recommended: The YubiKey 5 Series remains the gold standard for hardware-backed 2FA and passwordless sign-in on Windows 11 — the current 5.8 firmware stores up to 100 passkeys per key.
If you are wondering where to look for USB security keys, Microsoft offers an extensive list of FIDO2 security key providers. Here’s what you need to do to set it up and use a USB security key on your Microsoft Account and Windows 11.
Passkeys vs. security keys: what’s the difference in 2026?
This is the question everyone asks in 2026, so it’s worth clearing up before you spend $30 on a physical key. Both use the same FIDO2/WebAuthn cryptography, but the credential lives in different places:
- A passkey is a software credential stored in your device’s secure enclave (Windows Hello / TPM, Apple Secure Enclave, or Android StrongBox) and usually synced through an ecosystem — iCloud Keychain, Google Password Manager, or 1Password. It’s free, convenient, and syncs across your devices.
- A hardware security key (YubiKey, Titan, Feitian) stores the same kind of credential, but on a physical chip that never syncs anywhere. You have to plug it in or tap NFC to sign in.
NIST considers device-bound hardware keys AAL3 (the highest assurance level), while synced passkeys are AAL2. For most people, the ideal setup is both: use synced passkeys on your phone and laptop for day-to-day convenience, and keep a hardware key (plus one backup) as the phishing-proof recovery method that isn’t tied to a cloud account. If iCloud or your Google account ever gets locked, that hardware key is what gets you back in.
Practical rule: if you’re protecting an admin account, a crypto wallet, an email that owns other accounts, or anything a target-worthy attacker would love, get a physical key. Everything else is fine with a synced passkey.
Manage USB security key PIN in Windows Hello settings
If you ever want to change your USB security PIN or reset the USB security key back to factory settings, you can do that from within Windows Settings. Here’s what you need to do.
1. Go to Settings > Accounts > Sign-in options.
2. Under Ways to sign in, go to Security key and click Manage.
3. After you click Manage, a window will pop up prompting you to insert your USB security key. Insert your USB security key or tap your NFC reader to verify your identity on your Windows 11 PC now.
4. Once your USB security key is inserted and verified, you can either change the Security Key PIN or Reset Security Key to factory settings.
- Click Close when you are finished.
Add USB security key to your Microsoft Account
Here’s how to set up a USB security key on your Microsoft Account.
1. Set up a security key by signing into your Microsoft Account’s Security basics page in a browser.
2. Click “Get started” under Advanced security options.
3. Click Add a new way to sign in or verify.
4. Ensure that the USB device tab is selected, and your USB is inserted into your PC, then click Next to set up your USB security key.
5. Next, you will need to set up a PIN. Once you set up and confirm your PIN, click OK.
6. Finally, you need to name the USB security key so you can identify it later. Create a name for your USB security key and then click Next. I named my security key, “Security Key NFC by Yubico.”
- You’re all set! The next time you sign in, you can use your security key and PIN to sign into your Microsoft Account.
From here, you can add another security key or click Got it to be taken back to your Microsoft Account’s Security dashboard.
Once added, you will see your security key listed as a sign-in verification option under Ways to prove who you are.
You can add up to 10 physical security keys to your Microsoft Account. In practice, you want at least two: one on your keychain, one locked away as a backup.
Now, you can use your physical USB security key and PIN to sign into your Microsoft Account. Just plug in the USB to your PC, enter the PIN, and you will have access to your Microsoft Account and PC in no time at all.
💡 Prefer Google’s ecosystem? The Google Titan Security Key works the same way with Microsoft accounts, Google, GitHub, and any FIDO2 site — and Google’s newer Titan keys support up to 250 passkeys per device.
Common problems and fixes
- “Windows can’t find my security key.” Try a different USB port (front-panel USB-A on desktops is often unreliable), and make sure the key’s LED lights up. On USB-C only laptops, use a USB-C key like the YubiKey 5C NFC or a good-quality adapter.
- The security key option is grayed out under Sign-in options. You need to be signed in with a local admin account, and Windows Hello must already be set up on the PC. Enroll a Windows Hello PIN first, then add the key.
- Forgot the security key PIN. There’s no PIN recovery — you have to reset the key to factory settings using Manage > Reset Security Key, which wipes every passkey and credential stored on it. That’s why the backup key matters.
- “Passkey already exists” error when registering with Microsoft. Your account already has a passkey on that key. Sign in to account.microsoft.com/security, remove the old registration, and try again.
- NFC tap not registering on YubiKey 5 NFC/5C NFC with 5.7+ firmware. NFC is now off during shipping and activates the first time you plug the key in — plug it into a USB port once to unlock NFC.
- Lost your only key? Use your account recovery method (Microsoft Authenticator, backup codes, or SMS on your registered phone). This is exactly why you register at least two keys before you rely on the setup.
Pro tips for 2026
- Buy two keys at once. Register both to every account. Keep one on your keychain, one in a safe or drawer at home. Losing your only key means account recovery, which is painful and sometimes impossible for high-value accounts.
- Match connectors to your hardware. USB-C laptops want a USB-C key (YubiKey 5C NFC or 5C); older desktops want USB-A. The 5Ci has both USB-C and Lightning if you still use a Lightning-port iPhone or iPad.
- Consider a biometric key for shared PCs. The YubiKey Bio Series adds a fingerprint sensor so you don’t need to type the PIN at every login — useful in office environments.
- Enable enhanced PIN complexity if you’re rolling keys out for a team. YubiKey 5.7+ firmware can block trivial PINs like 1111 or 1234 at the hardware level.
- Store passkeys on the key, not just OTPs. With 100 passkey slots on 5.7+ firmware, one physical key can now replace your entire authenticator app for FIDO2-enabled sites.
- Register your key with critical accounts first: email, Microsoft account, GitHub, Google, financial accounts, and your password manager. Those are the accounts that let attackers pivot into everything else.
Have you tried out the YubiKey or another brand on Windows 11? Any problems with losing your USB drive or having it fail? Let us know in the comments below.
Related security guide
Want to turn a regular USB flash drive into a BitLocker startup key? That’s a completely different USB security trick — instead of protecting sign-in, it protects the encrypted drive itself so your PC won’t boot without the USB inserted.
Discover more from Microsoft News Now
Subscribe to get the latest posts sent to your email.










