Microsoft retires SMS and voice MFA on 1 February 2027. What actually qualifies

IronSightsStore
Apricorn Aegis Secure Key 3 2TB, product photo

Apricorn

Apricorn Aegis Secure Key 3 2TB

USB-A

Hardware-encrypted 2TB SSD with an on-board PIN keypad and no software to install. FIPS 140-2 Level 3, for sensitive data on the move.

$3,121.95incl. GST
On back order, ships in about 7 business days

On back order — ships in about 7 business days

We order it in from our distributor as soon as you buy. We charge today and confirm your order straight away; if that timing ever slips we will tell you, and you can cancel for a full refund any time before it ships.

Need it urgently? Get in touch and we will chase priority stock.

Postage
$9.95, free over $1,000
Delivery
2 to 6 business days
Returns
30 days, plus ACL rights
Invoice
Tax invoice on dispatch

“We engaged IronSights to help secure our Microsoft 365 environment, and the results have been outstanding. From start to finish, the process was handled with professionalism, clear communication, and deep technical expertise. The assessment gave us clarity on our risks and a practical path forward.”

Andrew, Technical Architect & CTOTechnology ConsultancyA client whose Microsoft 365 we secure

Buying for a team? We advise on which key fits and run the rollout, enrolment and Conditional Access included. Talk to us.

Good fit if

  • Regulated and government buyers who need FIPS 140-2 Level 3 storage
  • Moving large sensitive data sets between machines you don't control
  • Anyone who can't install encryption software on the host
  • Incident response and field work carrying big datasets in a pocket

Look elsewhere if

  • Teams needing a central console, remote wipe or audit logging
  • Fleet-wide endpoint encryption with policy and reporting
  • Hosts that are USB-C only
  • Cheap bulk storage where encryption isn't the point

The Aegis Secure Key 3 does its encryption in hardware. Real-time 256-bit AES-XTS runs on the device itself, and you unlock it with a PIN entered on the drive's own on-board keypad. Nothing is typed on the computer, and there is no software, app or driver to install. That makes it independent of the operating system, so it behaves the same on a machine you manage and one you have never seen before.

Because the PIN is entered on the drive and never reaches the host, a keylogger or screen grabber on the computer has nothing to capture. Get the PIN wrong too many times and the drive's brute-force defence wipes the encryption key, which leaves the data genuinely unrecoverable rather than simply locked away. The Aegis line is FIPS 140-2 Level 3 validated, the assurance benchmark most government and regulated buyers are told to look for.

For issuing drives to other people, you can set a separate admin PIN alongside the user's, force enrolment so the recipient sets their own PIN on first use, and switch the drive to read-only when you only need someone to read from it. That gives an administrator a degree of control without any host-side agent.

The headline is the capacity. Two terabytes of hardware-encrypted storage sits in a device small enough to share a keyring, with a plain USB-A connector and no setup on arrival. It is built for carrying large, sensitive data sets in a pocket rather than posting a laptop or a stack of disks.

Our take: this suits regulated work, incident response, and anyone who moves big data across machines they do not control. It is not a managed fleet tool. There is no central console, remote wipe or audit log, so if you need policy and reporting across many users, look at endpoint encryption instead.

Specifications

Encryption
256-bit AES-XTS, performed on the device in real time
Validation
FIPS 140-2 Level 3 (Aegis line)
Unlock
On-board keypad PIN; no host software or drivers
Capacity
2TB
Form factor
Keychain-scale SSD with integrated keypad
Connector
USB-A
Access controls
Separate admin and user PINs, read-only mode, forced enrolment
Brute-force defence
Encryption key wiped after a set number of wrong PINs

In the Apricorn Aegis encrypted storage

Same firmware and the same protocols across the range. What changes is the connector and whether it taps a phone.