This is a buying guide, not a configuration guide. It answers which keys to order and for whom. What to do with them inside the tenant is a separate piece of work, and a larger one than most people expect.
Break the staff list into four groups
Almost every Microsoft tenant sorts into the same four cohorts, and each one gets a different answer.
Global and privileged administrators. Hardware keys, two each, no exceptions. These accounts can change the identity configuration itself, which makes them the accounts an attacker wants and the accounts an assessor looks at first. A passkey in an app on a personal phone is not the right credential for someone who can turn off your Conditional Access policies.
Break-glass accounts. Their own dedicated hardware keys, two per account, stored separately from everyone's personal keys and excluded from the Conditional Access policies that could lock them out. These keys must work when the person who normally does this is unreachable, which means they cannot belong to that person.
General staff with a work phone. Passkeys in Microsoft Authenticator. Free, fast to deploy, and phishing-resistant. Buying keys for this group is usually money spent for no additional security.
Everyone the passkey route does not reach. Staff without a work phone, staff who decline a work app on a personal device, shared workstations, field and clinical roles. Hardware keys, two each. This group is why key orders exist, and it is nearly always smaller than people fear.
Which models
For the administrators and the staff on modern laptops, the 5C NFC. USB-C for the machine, NFC for the phone, one model covering both.
For anyone on USB-A desktops or docks, the 5 NFC.
For the second key of a desk-based person, the 5C Nano. It lives in the machine, does not occupy pocket space, and is the backup that never gets left at home.
For break-glass keys, use an NFC model rather than a Nano. A key in a safe that you can hand to someone is more useful in an emergency than one wedged in a computer.
Two models across the fleet is supportable. More than that becomes a support burden that outlasts the project.
The check to do before you order
Entra ID can restrict which security keys are permitted, by AAGUID, which is a model identifier the key presents when it registers. If that restriction is enabled and your chosen model is not on the list, registration fails and the keys are useless until someone changes the policy.
Check this first. It takes minutes and it is the most common reason a key order sits in a drawer for a fortnight.
What the keys do not do on their own
Ordering keys changes nothing until Conditional Access requires a phishing-resistant method for the accounts in scope.
That configuration is where the real work is, and where the real risk is. A Conditional Access policy applied too broadly, or without the break-glass exclusions in place, locks administrators out of their own tenant. It is a recoverable situation and it is not a pleasant one, and it is why we recommend that the policy change is planned rather than improvised.
We cover that as a Conditional Access review, and it usually sits alongside a broader Microsoft 365 review.