Microsoft retires SMS and voice MFA on 1 February 2027. What actually qualifies

IronSightsStore
YubiKey 5 Nano FIPS (140-3), product photo

Yubico

YubiKey 5 Nano FIPS (140-3)

USB-A · no NFC · Firmware 5.7

FIPS 140-3 validated YubiKey in a USB-A nano that stays in the port. The certification regulated and government buyers need.

$167.95incl. GST
In stock, ships today if ordered by 12pm AEST
Postage
$9.95, free over $1,000
Delivery
2 to 6 business days
Returns
30 days, plus ACL rights
Invoice
Tax invoice on dispatch

“We engaged IronSights to help secure our Microsoft 365 environment, and the results have been outstanding. From start to finish, the process was handled with professionalism, clear communication, and deep technical expertise. The assessment gave us clarity on our risks and a practical path forward.”

Andrew, Technical Architect & CTOTechnology ConsultancyA client whose Microsoft 365 we secure

Buying for a team? We advise on which key fits and run the rollout, enrolment and Conditional Access included. Talk to us.

Good fit if

  • Regulated or government buyers who must show FIPS-validated authenticators on the paperwork
  • Desktop and workstation users who leave the key plugged in permanently
  • Organisations standardising on phishing-resistant MFA across Microsoft 365 / Entra ID

Look elsewhere if

  • Anyone without a compliance requirement (the standard YubiKey 5 is the same hardware)
  • Mobile-first users who need to tap a phone (there is no NFC)
  • USB-C laptops, or people who hot-desk between machines

The YubiKey 5 Nano FIPS is the certified sibling of the standard 5 Nano. The hardware and the protocols are identical; the difference is the paperwork. This key is FIPS 140-3 validated, the current US federal standard that replaces the 140-2 generation now being retired. If a contract, a government tender or an internal control says your authenticators must be FIPS validated, this is the version that satisfies the auditor. If nothing you sign asks for it, the standard YubiKey 5 will serve you just as well.

Physically it is a nano: a stub of USB-A that sits almost flush with the port and stays there. It is built for a fixed desktop or workstation that one person uses and does not want to unplug daily. There is no battery and no moving parts, and the key is crush- and water-resistant, so leaving it in the machine year-round is the intended use rather than a risk.

Running firmware 5.7, it carries the full YubiKey 5 protocol set: FIDO2 and WebAuthn for passkeys, FIDO U2F, PIV smart card, OATH-TOTP and OATH-HOTP, OpenPGP, YubiKey OTP, static password and HMAC-SHA1 challenge-response. That covers phishing-resistant sign-in to Microsoft 365 and Entra ID, smart-card login, and one-time codes for services that still rely on them, from a single key.

Our take: buy it when a compliance requirement genuinely names FIPS, and when the key will live in a desk-bound machine. It has no NFC, so it will not tap a phone, and it is USB-A, so it suits desktops rather than newer USB-C laptops. A nano is easy to forget and awkward to move between machines; if your people hot-desk or work from laptops, choose a larger or USB-C key instead.

Specifications

Certification
FIPS 140-3 validated (replaces the retiring 140-2 generation)
Series
YubiKey 5 FIPS Series
Firmware
5.7
Connector
USB-A
Form factor
Nano, sits almost flush and stays in the port
NFC
None
Protocols
FIDO2/WebAuthn, FIDO U2F, PIV, OATH-TOTP/HOTP, OpenPGP, YubiKey OTP, static password, HMAC-SHA1 challenge-response
Build
Crush- and water-resistant, no battery, no moving parts

In the YubiKey 5 FIPS 140-3 Series

Same firmware and the same protocols across the range. What changes is the connector and whether it taps a phone.