YUBIKEY × DTI — ENTERPRISE AUTHENTICATION
Enterprise Passwordless SSO: Phishing-Resistant Login with Hardware Security Keys
Replace passwords and OTPs with FIDO2 authentication on YubiKey, natively integrated with Microsoft Entra ID, Google Workspace, and Okta. One touch on a hardware security key unlocks your entire enterprise application estate — with no credentials left to steal, guess, or phish. DTI supports you from assessment and pilot through organization-wide rollout.
Enterprise passwordless SSO is no longer a convenience play — it is a direct response to the fact that most account-compromise incidents begin with stolen credentials. As long as your organization relies on passwords, your largest attack surface is human: employees reusing passwords, falling for fake login pages, or approving MFA prompts out of fatigue. Single sign-on combined with passwordless authentication built on the FIDO2 standard removes the root cause, because there is no shared secret left for attackers to harvest.
For enterprises operating in Indonesia, the urgency is reinforced by regulation. Government Regulation 71/2019 on Electronic Systems and Transactions requires electronic system operators to keep their systems reliable, secure, and accountable, while Law No. 27 of 2022 on Personal Data Protection requires data controllers to implement technical measures against unauthorized access to personal data. Illegal access to electronic systems is likewise a prohibited act under the Electronic Information and Transactions Law (UU ITE). Phishing-resistant authentication with hardware security keys is one of the most effective technical controls available to meet these access-security obligations — particularly for regulated sectors such as financial services, which are subject to OJK provisions on IT operations and IT risk management.
YubiKey is a hardware security key implementing the open FIDO2/WebAuthn standard — the same standard natively supported by Microsoft Entra ID, Google Workspace, and Okta. Unlike SMS OTPs or authenticator apps, FIDO2 credentials are cryptographically bound to the legitimate service domain, so a lookalike phishing page can never obtain a valid credential. As an implementation partner in Indonesia, DTI helps you design an end-to-end passwordless SSO architecture: selecting the right YubiKey variants (including the FIPS series for stringent compliance needs), integrating your identity providers, defining enrollment and recovery policies, and running day-to-day operations.
Why Passwords and OTPs Are No Longer Enough for the Enterprise
Phishing and credential theft
Fake login pages and adversary-in-the-middle attacks can capture passwords and OTP codes in real time. As long as authentication depends on a secret that is typed or copied, attackers retain a way in.
OTP and push-based MFA can still be defeated
SMS OTPs are exposed to SIM swapping and interception, while push notifications are vulnerable to MFA fatigue — attackers flood employees with approval requests until one gets through. Neither qualifies as phishing-resistant under NIST SP 800-63B.
Privileged access without matching protection
Domain administrators, DevOps engineers, and core-system operators are often protected by the same mechanisms as ordinary accounts. A single leaked privileged credential can lead to full infrastructure takeover.
Operational burden and weak audit trails
Password resets weigh on the helpdesk, while complex password policies push users toward insecure workarounds. Without strong, centralized authentication, proving who accessed what during an audit becomes difficult.
DTI's YubiKey-Based Passwordless SSO Solution
Phishing-resistant FIDO2/WebAuthn authentication
Cryptographic credentials live inside the YubiKey and are bound to the genuine service domain, so they cannot be harvested, replayed, or used on a spoofed site. Private keys never leave the device.
Native Microsoft Entra ID integration
YubiKey is supported as a FIDO2/passkey sign-in method in Microsoft Entra ID, covering access to Microsoft 365 and federated applications. Conditional Access policies can require phishing-resistant authentication for high-risk applications and roles.
Google Workspace and Okta support
Google Workspace supports security keys for 2-Step Verification and for its strengthened protection program aimed at high-risk accounts, while Okta accepts YubiKey as a FIDO2/WebAuthn authenticator within adaptive MFA policies. The same key can serve multiple ecosystems at once.
Protection for privileged access and critical systems
Enforce step-up policies so administrator accounts, production-server access, and sensitive transaction approvals can only proceed with a hardware key. YubiKey also supports PIV/smart card, OpenPGP, and OTP for scenarios beyond WebAuthn.
Compliance readiness with the FIPS series
For stringent compliance requirements, the YubiKey FIPS series is FIPS 140-2 validated, aligning with NIST SP 800-63B, which places phishing-resistant hardware authenticators at its highest assurance level. DTI helps map device choices to your obligations under GR 71/2019, the Personal Data Protection Law, and sector-specific rules.
DTI has supported enterprises and institutions in Indonesia's regulated sectors in deploying strong authentication and securing access to critical systems.
How DTI Implements Passwordless SSO in Your Organization
Identity assessment and risk mapping
DTI maps the identity providers you run (Entra ID, Google Workspace, Okta, or a combination), your application inventory, and user groups by risk — starting with privileged accounts, executives, and holders of personal-data access. The output is an authentication architecture blueprint and a prioritized rollout sequence.
Identity provider integration and access policies
We configure FIDO2 authentication methods on your IdP, define conditional access policies (for example, mandating phishing-resistant authentication for critical applications), and set up SSO federation so a single strong authentication opens every application a user is entitled to.
Pilot, enrollment, and recovery procedures
A pilot group enrolls their YubiKeys under documented procedures, including backup-key policy and the recovery flow for lost devices — the single factor that most often determines whether a passwordless program succeeds. Pilot feedback refines the policies before expansion.
Phased rollout and ongoing operations
Rollout expands unit by unit with user-education materials, adoption dashboards, and progressively tightened policies until passwords can be removed or demoted. DTI stays engaged for operations: device procurement, key replacement, and policy tuning as your organization evolves.
Frequently Asked Questions
How does FIDO2 authentication differ from OTPs or authenticator apps?
OTPs and authenticator-app codes are still secrets the user types in, so they can be stolen through phishing pages or adversary-in-the-middle attacks. With FIDO2, authentication is a cryptographic signature bound to the legitimate service domain — a fake site can never obtain a valid response. This is why NIST SP 800-63B classifies such authenticators as phishing-resistant.
What happens if an employee loses their YubiKey?
Standard practice is to enroll at least two keys per user (primary and backup) and to establish an identity-verified recovery flow, for example through the helpdesk with layered checks. A lost key is simply revoked in the identity provider and becomes immediately unusable, with no need to reset the entire account. DTI helps design this lifecycle policy from the pilot phase onward.
Is passwordless SSO with hardware keys mandated by Indonesian regulation?
No Indonesian regulation explicitly mandates this specific method. However, GR 71/2019 requires electronic systems to be secured and the Personal Data Protection Law requires technical measures against unauthorized access to personal data, while sectoral regulators such as OJK expect sound IT risk management. Phishing-resistant authentication is one of the strongest available ways to satisfy those obligations and to strengthen your position in audits.
Can one YubiKey be used across Microsoft Entra ID, Google Workspace, and Okta at the same time?
Yes. FIDO2/WebAuthn is an open standard, and a single YubiKey can hold credentials for many services simultaneously without interference. This suits organizations with hybrid environments — for example, email on Google Workspace while internal applications federate through Entra ID or Okta.
What about legacy applications that do not support WebAuthn?
The common approach is to place legacy applications behind your identity provider via federation (SAML/OIDC) or an access gateway, so strong authentication happens at the IdP layer. For specific scenarios, YubiKey also supports PIV/smart card and OTP protocols that older systems accept more readily. DTI maps the best option per application during the assessment phase.
How long does an enterprise passwordless SSO implementation usually take?
The timeline depends on the number of identity providers, application complexity, and user scope — which is why DTI always starts with a pilot on a limited group before full rollout. This phased approach delivers security value early, especially when privileged accounts are prioritized first, without disrupting daily operations.
YUBIKEY × DTI — ENTERPRISE AUTHENTICATION
Start Your Organization's Passwordless Journey
Discuss a passwordless SSO architecture that fits your identity providers, risk profile, and compliance obligations. The DTI team is ready to help from initial assessment through a YubiKey pilot in your environment — with no commitment at the consultation stage.
