The instinct is to multiply headcount by two and flinch at the number. Almost nobody needs that, and working out the real figure usually turns a project people were putting off into one they can approve this week.
Start with scope, not headcount
Not every account needs a hardware key. Most organisations cover general staff with passkeys, which cost nothing, and buy keys for the accounts and people that passkeys do not suit.
So the question is not how many staff you have. It is how many of these you have.
Privileged accounts. Global administrators, security administrators, anyone who can change identity configuration. This group is smaller than most people guess, and if it is not, that is its own finding.
Finance and payments. Whoever can move money or change bank details.
Staff the passkey model cannot reach. Anyone without a work phone, anyone who declines to install a work app on a personal device, shared workstations, and roles where phones are impractical or not permitted.
Break-glass accounts. Usually two, sometimes more.
Add those up. That is your user count, and it is normally a fraction of your staff list.
Then apply the multiplier
Two keys per person in scope. This is not padding. A single key is a lockout waiting to happen, and the recovery process you fall back on is weaker than the credential you just bought, which defeats the purpose of buying it.
Break-glass accounts get their own dedicated pair each, stored separately from everything else. Do not reuse someone's personal keys for this. The whole point is that they work when that person is unavailable.
Add a spare pool
Hold a handful of unregistered keys with whoever runs IT.
The reason is speed. When someone loses a key, the window where they are down to one is the window where a second loss becomes a real incident. A spare handed over the same day closes it. A spare that requires a purchase order leaves it open for a fortnight.
Somewhere around one spare per ten people in scope works for most organisations, with a floor of two so the pool is never empty after a single incident.
A worked example
Take a forty person business.
Six privileged accounts. Three people in finance. Eight staff on shared workstations in a warehouse with no work phones. Two break-glass accounts.
That is seventeen users in scope, so thirty-four keys, plus four for the break-glass pairs, plus four spares. Forty-two keys for a forty person business, which sounds like one each and is not distributed that way at all.
Do the same arithmetic with your own numbers before you assume it is unaffordable.
What to actually order
For staff on modern laptops who also sign in on a phone, the 5C NFC. It covers the most situations with one model.
For USB-A machines, the 5 NFC.
For the second key of any desk-based person, the 5C Nano is a good choice. It lives permanently in a desktop, costs no pocket space, and is the backup that never gets left at home.
Standardise where you can. A fleet with two models is supportable. A fleet with six is a help desk problem waiting to happen.
Before you order
Two things are worth checking, because both change the quantity.
Whether your tenant restricts which key models are permitted, which in Entra ID is done by AAGUID. Ordering a model your own policy rejects is an avoidable week.
And which accounts are genuinely in scope, which is the number the whole calculation rests on. Getting that wrong in either direction is expensive, and it is the substance of a Conditional Access review.