Microsoft retires SMS and voice MFA on 1 February 2027. What actually qualifies

IronSightsStore

What happens if you lose your YubiKey?

Nothing catastrophic, if you prepared. What a lost key does and does not expose, what to do in the first hour, and how to make it a non-event.

IronSights Editorial ·

This is the question that stops people buying, so here is the answer up front.

If you prepared, losing a key is an administrative chore. If you did not, it is a bad day that ends in an account recovery process you will not enjoy.

The difference is entirely whether you bought a second key.

What a lost key does not do

Someone who finds your key cannot read your accounts off it. There is no list of sites on it, no usernames, no passwords. The credentials are cryptographic keys that never leave the device, and they only respond to the exact domain they were created for.

If the key required a PIN or a fingerprint, the finder needs that too. Without it, the key does nothing useful for the accounts that demanded user verification.

And a security key is a second factor. Whoever has it still needs the password or the account it belongs to, and they have no way of knowing which accounts that is.

So a lost key is not an open door. It is a lost second factor, which is a problem about your access rather than about their access.

What it does do

It takes away your way in.

If it was your only registered key, you are now relying on whatever backup method the account offers. Recovery codes if you saved them, a phone number, a service desk call. Those paths are weaker than the key you just lost, which is the awkward part of the whole situation.

The first hour

Sign in with your backup key. That is the whole point of having one.

Then remove the lost key from every account it was registered to. Every service that supports security keys lets you see which keys are registered and delete one. Do this even though the finder almost certainly cannot use it, because tidy is better than probably-fine.

Order a replacement immediately and make it your new backup. Getting back to two keys is the priority, and the window where you are down to one is the window where this happens again with worse consequences.

If it was a work key, tell whoever runs IT. On a managed tenant they may want to revoke the credential centrally and check whether the key had access to anything that deserves a closer look.

If you only had one key

Work through it in this order.

Recovery codes first, if you saved them when you set up the account. This is what they are for and it is the fastest route.

Then any other registered method: an authenticator app, a passkey on your phone, a backup email. Anything that gets you in without the key.

Then the service's account recovery process, which is slow by design and will ask you to prove who you are.

For a work account, the service desk. Expect identity checks, and understand why they are being thorough. This step is exactly the one attackers imitate.

Once you are back in, buy two keys.

Making it a non-event

The prepared version of this whole article is four sentences.

Buy two keys. Register both to every account that matters, at the same sitting. Keep the second one somewhere you can reach but that does not travel with the first. Test it once so you know it works.

Do that and a lost key costs you a replacement and ten minutes of tidying up.

For a business, add a small pool of spare keys held by IT so a replacement is handed over the same day, and give break-glass accounts their own dedicated pair stored separately. Mapping that out for a specific set of privileged roles is part of a Conditional Access review.

Frequently asked questions

  1. Can someone use my lost YubiKey to get into my accounts?

    Not on its own. They would also need your password, and for accounts requiring user verification, your PIN or fingerprint. They also have no way to know which accounts the key belongs to.

  2. Should I wipe a lost key remotely?

    There is no remote wipe for a security key. Remove it from your accounts instead, which achieves the same result from your side.

  3. What if I find the key later?

    Register it again as a spare if you like, or keep it as a third. There is no harm in it once it has been removed and re-added deliberately.

  4. How do I avoid this entirely?

    Two keys, both registered, one of them somewhere that does not travel with the other. That is the whole prevention strategy.