Microsoft retires SMS and voice MFA on 1 February 2027. What actually qualifies

IronSightsStore

The two-key rule: one on your keyring, one in the safe

A single security key is a lockout waiting to happen. How to pick the pair, where the second one lives, and how to register both properly.

IronSights Editorial ·

Buy two keys. If you take one thing from this store, take that.

The reasoning is short. A security key is deliberately impossible to copy. That property is the entire point, and it is also the reason a single key is dangerous. Lose it, break it, leave it in a hotel room, and the credential is gone with no way to reconstruct it. What you fall back on at that moment is account recovery, which is the weakest and most attacked part of any sign-in system.

A second key turns an emergency into an inconvenience.

Why account recovery is the wrong safety net

Think about what happens when your only key disappears.

On a personal account, you are into recovery codes if you saved them, or into an automated recovery flow if you did not. Those flows are designed to help people who genuinely cannot get in, which means they are also the path an attacker takes when they want in.

On a work account, you are into a call to the service desk. That call is the step attackers have targeted repeatedly against large organisations, because persuading a busy human is cheaper and more reliable than defeating cryptography. Every time your recovery process runs for a real reason, it also runs for a reason someone could fake.

You bought a phishing-resistant credential to close that door. Losing your only key opens it again.

Picking the pair

The two keys do different jobs, so they do not need to be the same model.

The first key travels. It goes on your keyring or in your bag, and it does the daily work. An NFC model suits this, because the travelling key is the one that ends up tapping against a phone. That is the 5C NFC for a modern laptop, or the 5 NFC if your machines are USB-A.

The second key stays put. It never leaves a building, so it does not need to be comfortable to carry. The 5C Nano is built for this. It sits nearly flush in a port and lives in a desktop or a docked machine you can always reach.

If you would rather the backup sat in a safe than in a computer, buy a second NFC model instead. A key in a drawer is easier to hand to a colleague during an emergency than a key wedged in someone's desktop.

Where the second key should live

Pick a location you can get to on a bad day, and be specific about it.

For an individual, a home desktop or a drawer at home works. For a business, the answer is usually a locked cabinet or a safe that more than one person can open, with a register of which key belongs to whom.

The failure to avoid is storing the backup somewhere that shares a fate with the first. Both keys in the same laptop bag is one bag away from having no keys. A backup in the office when the office is what you cannot get into is not a backup.

Register both at the same time

This is the part people skip, and it is the part that makes the second key worthless.

A backup key protects nothing until it has been registered to the accounts it is meant to protect. Registering it later, after you have lost the first one, is exactly the scenario the backup was supposed to prevent.

So do it in one sitting. For each account that matters, add both keys before you move on. It takes a few minutes per account and it is much easier while you are holding both keys and are already in the security settings.

Then test the backup at least once. Sign in with it. A key you have never used is a key you are trusting on faith.

How many for a business

Two per person is the floor, not a target.

Beyond that, hold a small pool of spares with whoever runs IT, so a lost key is a replacement handed over the same day rather than a procurement exercise. And register a dedicated pair to your break-glass accounts, stored separately from everything else, tested on a schedule.

If you want the arithmetic for a specific headcount and a specific set of privileged roles, that is something our team works through as part of a Conditional Access review.

Frequently asked questions

  1. Can I register two keys to the same account?

    Yes, and nearly every service that supports security keys allows it. Some allow many more than two.

  2. Should both keys be the same model?

    They do not need to be. A common pairing is an NFC model that travels and a Nano that lives in a desktop.

  3. What if I lose the first key?

    Sign in with the backup, remove the lost key from each account, and register a replacement as the new backup. Getting back to two keys is the priority, not the cleanup.

  4. Do I need a third key?

    Most individuals do not. Businesses often keep spares in a pool so a replacement is immediate, and break-glass accounts usually get their own dedicated pair.