Duo Security & Yubico partner to protect Facebook employees

Protecting your organization does not need to be complicated, frustrating or costly. The simple addition of strong authentication paired with seamless identity access management can significantly reduce security risks across an entire organization by making it simple to deploy and easy for employees to use. A recent collaboration between Yubico and Duo Security show us how.

The focus on a strong, simple authentication experience is something Duo Security and Yubico have offered together since 2013, when a security need from Facebook sparked the partnership. Facebook needed to provide secure, simple, and seamless authentication to all their employees. They also needed support for frequent logins and quick deployment to 30,000+ employees with minimal overhead and support costs. After careful consideration, the company looked to the advanced authentication solutions provided by both Duo Security and Yubico. Together, our joint solution addressed Facebook’s authentication priorities—placing equal emphasis on usability and security.

“Organizations are looking for flexible options that can meet the needs of a diverse and mobile workforce, and more often than not, they are looking to several solutions to do so,” said Jerrod Chong, VP of Product at Yubico. “That is why Yubico’s integration with Duo Security is one that we, and our customers, value. Together, through the use of the YubiKey and cloud-based authentication on the backend, we’re able to provide a seamless, flexible, and highly-secure authentication experience.”

Both Yubico and Duo Security support the FIDO Universal 2nd Factor (U2F), a two-factor authentication (2FA) security protocol developed by Yubico and Google that effectively defends against phishing and man-in-the middle (MitM) attacks. In June 2017, the National Institute of Standards and Technology (NIST) recognized FIDO U2F at the highest Authenticator Assurance Level (AAL3) in their NIST Special Publication 800-63 Revision3.

“At Duo, we place a heavy focus on end user experience. From frictionless user experiences to quick and seamless deployments, we aim to make authentication with Duo Security exceptionally easy,” said Ash Devata, VP of Product at Duo Security. “At the same time, we take security seriously and constantly improve authentication effectiveness. This is exactly why we added support for the YubiKey and FIDO U2F. As a globally recognized leading authentication standard, U2F is something we absolutely want our customers having access to.”

Duo Security Logo
Ecosystem Showcase: Duo Security

In addition to FIDO U2F, the YubiKey and Duo Security support other authentication protocols including Yubico OTP (one time password), PIV (smart card), OpenPGP, and more. This functionality is loved by joint customers for the flexibility to choose 2FA methods that fit the needs of a diverse user base. The YubiKey provides an easy-to-use and secure way to protect applications that support FIDO U2F standards, as well as additional applications such as VPNs, SSH, RDP, and more, using the same physical form factor.

Learn more about utilizing the YubiKey and FIDO U2F with Duo Security, instructions are provided during the initial Duo self-enrollment process. If you are already enrolled in Duo Security using a different device for two factor authentication, such as your mobile phone, you can add a YubiKey (security token) as an additional authentication device from the device management portal.

New to Duo Security? Learn more about their 2FA and trusted access options for the enterprise. You can get a free trial.

Don’t have a YubiKey? Learn more about securing digital identities, computers, servers, mobile devices, and online services with the YubiKey. Check out the full YubiKey product lineup to find the right key for you.

Talk to our teamTalk to our team

Share this article:


  • Q&A with Yubico’s CEO: Our move to the main Nasdaq market in StockholmAs 2024 draws to a close, it’s the perfect time to reflect on the incredible journey we’ve had this year and how it has shaped where we stand today as a company. To mark this moment, I sat down with our CEO, Mattias Danielsson, to look back on the milestones and achievements of 2024—culminating in […]Read moreCEOMattias Danielsson
  • Exploring DORA: A look at the next major EU mandateFinancial institutions have historically managed operational risk using capital allocation, but under EU Regulation 2022/2554 – also known as the Digital Operational Resilience Act (DORA) – the financial sector and associated entities in the European Economic Area (EEA) must also soon follow new rules. These new rules focus on the protection, detection, containment, and the […]Read moreDORAEU
  • Securing critical infrastructure from modern cyber threats with phishing-resistant authenticationAcross the globe, 2024 has seen a whirlwind of change. With ongoing wars, recent political change-ups and more, growth in data breaches targeting critical infrastructure continue to be on the rise. Critical infrastructure is integral to our everyday life – from the energy and natural resources powering our hospitals and providing clean drinking water, telco […]Read moreCISAcritical infrastructurezero trust
  • surface blog crownMicrosofts Surface Pro 10 möjliggör NFC-baserad lösenordsfri inloggning med YubiKeys, för företagDra fördel av det långvariga samarbetet mellan Microsoft och Yubico genom att distribuera YubiKeys tillsammans med den nya Surface Pro 10 enheten för ditt företag. Read morenfcpasswordless