Microsoft retires SMS and voice MFA on 1 February 2027. What actually qualifies

IronSightsStore
YubiHSM 2 FIPS, product photo

Yubico

YubiHSM 2 FIPS

USB-A · no NFC

A FIPS 140-3 hardware security module for servers: keep your CA and signing keys off the disk and inside tamper-resistant hardware.

$1,628.95incl. GST
On back order, ships in about 7 business days

On back order — ships in about 7 business days

We order it in from our distributor as soon as you buy. We charge today and confirm your order straight away; if that timing ever slips we will tell you, and you can cancel for a full refund any time before it ships.

Need it urgently? Get in touch and we will chase priority stock.

Postage
$9.95, free over $1,000
Delivery
2 to 6 business days
Returns
30 days, plus ACL rights
Invoice
Tax invoice on dispatch

“We engaged IronSights to help secure our Microsoft 365 environment, and the results have been outstanding. From start to finish, the process was handled with professionalism, clear communication, and deep technical expertise. The assessment gave us clarity on our risks and a practical path forward.”

Andrew, Technical Architect & CTOTechnology ConsultancyA client whose Microsoft 365 we secure

Buying for a team? We advise on which key fits and run the rollout, enrolment and Conditional Access included. Talk to us.

Good fit if

  • Teams protecting a private Certificate Authority such as Microsoft AD CS
  • Organisations that must prove where signing keys physically live for audit or IRAP
  • Servers needing hardware-backed encryption, secrets protection, or code and document signing

Look elsewhere if

  • Staff who just need passwordless or phishing-resistant login (buy a YubiKey instead)
  • Anyone wanting a device to carry on a keyring
  • Setups with no one to own key backup and HSM redundancy

The YubiHSM 2 is a hardware security module, not a login key. Despite the nano USB-A shape it shares with a YubiKey, this is server infrastructure. It slots into a server or a secured management workstation and stays there. Its one job is to generate cryptographic keys and hold them inside dedicated tamper-resistant hardware, so your private keys never sit in plaintext on the machine where an attacker who owns the box could read them.

The clearest reason to buy one is a private Certificate Authority. If you run Microsoft AD CS, the CA signing key is the single most valuable secret in your environment: anyone who copies it can mint trusted certificates at will. Keep that key inside a YubiHSM 2 and it cannot be exported or lifted off the server, even by an administrator. Signing still happens on demand; the key itself never leaves the hardware.

Beyond a CA, teams use it for code and document signing, database and secrets encryption, and hardware-backed key storage for their own applications. It talks to your stack through PKCS#11 and Microsoft CNG/KSP, so it fits the standard Windows and cross-platform ways of asking an HSM to do the cryptography for you.

It is FIPS 140-3 validated, which is often the point. For regulated buyers, IRAP-aligned work, or anyone who has to show where a signing key physically lives, a validated module turns 'we keep it safe' into something you can evidence during an audit.

Our take: this is a considered purchase, not an impulse one. Someone has to decide where the module sits, how keys are backed up or wrapped, and what happens if the unit fails, which usually means buying a second one for redundancy. It is worth the effort when a key genuinely must not leave your control. If you only need staff to log in without passwords, you want a YubiKey, not this.

Specifications

Type
Hardware security module (HSM)
Form factor
Nano USB-A
Deployment
Installed in a server or secured management workstation
Key protection
Keys generated and stored in tamper-resistant hardware; private keys never held in plaintext
Interfaces
PKCS#11 and Microsoft CNG/KSP
Validation
FIPS 140-3 validated
Typical uses
Private CA protection, signing, database and secrets encryption, application key storage