Skip to main content
DTI

YUBIKEY — YUBICO PREFERRED PARTNER

Enterprise Hardware MFA: Phishing-Resistant Security Keys for Your Organization

Protect employee identities and privileged accounts with FIDO2 hardware security keys — authentication that cannot be phished. DTI, a Yubico Preferred Partner, guides your organization from assessment to a managed rollout across Microsoft 365 and Google Workspace.

FIDO2 / WebAuthnFIPS 140-2 (YubiKey FIPS series)POJK 11/2022 (risk-based)UU PDP No. 27/2022

Discuss your deployment

Free initial consultation — we'll map your needs, integration, and compliance.

Are you inquiring for an organization or yourself?*

✓ Official 1-year Yubico warranty — claims handled by DTI in Indonesia

Reply within 1 business day · Your data is protected (UU PDP)

Enterprise hardware MFA has become the real dividing line between organizations that merely have multi-factor authentication and organizations that are genuinely resistant to account takeover. SMS one-time codes and authenticator apps do add a layer of security, but both can still be handed over to a fake login page by the victim. Hardware security keys close that gap at the protocol level: credentials are cryptographically bound to the legitimate domain, so there is no code to steal and nothing to relay.

The threats facing Indonesian enterprises have shifted from simple phishing to adversary-in-the-middle attacks: fake proxies that relay the real login page, capture the session, and bypass OTP in real time — compounded by MFA fatigue tactics that bombard employees with approval prompts until one gets through. Against both patterns, code-based and push-based authentication have structural limitations that no amount of security awareness training can fix.

Indonesian regulation points in the same direction. POJK 11/2022 requires commercial banks to apply risk-based IT security controls, including adequate access management; the Personal Data Protection Law (UU PDP No. 27/2022) demands technical measures to protect personal data; and PP 71/2019 obliges electronic system operators to secure their systems. No regulation mandates one specific MFA method — but the risk-based approach makes phishing-resistant authentication the easiest control to defend before auditors and regulators, especially for critical access.

Why Code-Based MFA Is No Longer Enough

OTP and push notifications can still be phished

Adversary-in-the-middle attacks relay the genuine login page and capture OTPs and session cookies in real time. Even your most vigilant employees struggle to tell a fake proxy from the legitimate domain.

MFA fatigue turns people into the weak point

Attackers bombard employees with repeated approval prompts until one is accepted — and one approval is all it takes. Controls that depend on user vigilance fail at enterprise scale.

Privileged accounts are the highest-value target

Domain administrators, cloud console accounts, and core-system operators hand an attacker full control if compromised. These accounts demand authentication assurance well above standard employee MFA.

MFA rollouts often stall halfway

Without enrollment planning, fallback policies, and device-replacement procedures, hardware MFA initiatives get stuck at the pilot stage. The rest of the user population stays on weak methods — and the gap stays open.

Hardware Security Keys Run as a Program, Not Just a Device Purchase

Phishing resistance at the protocol level

FIDO2/WebAuthn cryptographically binds credentials to the legitimate domain — there is no code to steal and no approval to trick. However convincing the fake page, it gets nothing.

Native Microsoft 365 and Google Workspace integration

YubiKey is supported directly by Microsoft Entra ID and Google Workspace with no additional middleware, including as a passkey. The same key also works across hundreds of other FIDO2-enabled services.

Dedicated protection for privileged accounts

Enforce policies requiring security keys for administrators, server access, and cloud consoles — including smart card (PIV) scenarios where environments demand it. Critical access no longer rests on passwords and OTP.

Managed rollout by DTI

DTI designs your enrollment policy, backup keys, lost-key procedures, and phased migration by user group. You get a completed adoption program, not a stack of devices in a storeroom.

Compliance support and FIPS series

For government agencies and banking environments that require validated cryptography, the YubiKey FIPS series (FIPS 140-2 validated) is available. DTI helps map your authentication controls to POJK, UU PDP, and ISO/IEC 27001 frameworks.

DTI has guided organizations in Indonesia's banking and enterprise sectors through hardware security key implementations, from limited pilots to privileged-account rollouts.

How DTI Runs Your Hardware MFA Rollout

1

Assessment and policy design

We map your user population, applications, and identity provider (Entra ID, Google Workspace, or another IdP), then design authentication policy by risk tier — from privileged accounts down to general staff — including the right key form factors (USB-A, USB-C, NFC).

2

Controlled pilot

The rollout starts with a small, highest-risk group, typically IT teams and administrators. Enrollment procedures, backup keys, and lost-key scenarios are tested to maturity here before anything is scaled.

3

Phased rollout and enrollment

Users are enrolled in waves with clear guidance, conditional access policies are tightened progressively, and weak methods (SMS OTP) are disabled as each group completes migration — leaving no fallback path behind.

4

Operations and lifecycle

DTI supports ongoing operations: replacing lost or damaged keys, onboarding new employees, revoking access at offboarding, and documenting controls for internal audit and regulatory examinations.

Frequently Asked Questions

How is a hardware security key different from an authenticator app or SMS OTP?

Authenticator apps and SMS OTP generate codes that victims can still hand over to a fake page, or that an adversary-in-the-middle proxy can intercept. A FIDO2 security key performs cryptographic authentication bound to the legitimate domain, so the credential simply does not work on an impostor site — the protection operates at the protocol level rather than depending on user vigilance.

Do Indonesian regulators mandate FIDO2 or hardware security keys?

No. POJK 11/2022 and related regulations impose risk-based security obligations rather than mandating any specific authentication method. But precisely because the approach is risk-based, phishing-resistant authentication for critical access is the control that is easiest to defend during audits and regulatory examinations.

Is YubiKey compatible with Microsoft 365 and Google Workspace?

Yes. Microsoft Entra ID and Google Workspace support FIDO2/WebAuthn natively, including passkey mode, so YubiKey works for SSO without additional middleware. The same key also serves other FIDO2-enabled services, and smart card (PIV) and OTP modes are available for specific scenarios.

What happens if an employee loses their security key?

Standard practice is for every user to have a registered backup key, so a lost key is simply revoked in the identity provider without interrupting work. DTI builds the reporting, revocation, and replacement procedures in from the design stage — a lost device becomes an administrative event, not a security incident.

How long does a hardware MFA rollout take for a large organization?

Duration depends on user count, identity provider readiness, and application scope — so we do not promise a one-size-fits-all number. Our pattern is always phased: pilot with the highest-risk group first, then rollout waves by business unit, so the security value arrives in the first weeks rather than at the end.

Is there a version for institutions that require FIPS validation?

Yes, the YubiKey FIPS series uses FIPS 140-2 validated cryptography and is the common choice for government agencies and banking environments with strict requirements. DTI helps you determine whether the standard or FIPS series is right based on the compliance requirements that actually apply to your organization.

YUBIKEY — YUBICO PREFERRED PARTNER

Discuss Your Enterprise Hardware MFA Rollout

Tell us about your identity provider and user population. The DTI team will prepare an authentication policy recommendation, YubiKey series options, and a phased rollout plan — the initial consultation is free.

Chat via WhatsApp