SYNRION x.ID · IT-SA 2026 · YUBIKEY INVENTORY

What’s on your YubiKeys?

One key can hold multiple identities, certificates and passkeys. SYNRION x.ID makes their relationship visible in the portal for employees and authorized company administrators. At it-sa 2026, central FIDO2 inventory on YubiKey firmware 5.8 or later extends the central PIV inventory.

VALUE IN 30 SECONDS

One YubiKey. Multiple identities. One central view.

01

Employees understand their key

Employees see their assigned keys and identities in the personal portal. Certificates and stored FIDO2 passkeys appear in an understandable context.

02

Companies gain a central view

Authorized administrators connect the company, users, identities and physical YubiKey with its recorded PIV and FIDO2 inventory.

03

Inventory becomes operational evidence

Inventory collection becomes part of certificate replacement, FIDO2 provisioning and other lifecycle operations. Assignments, changes and the time of inspection support policy reviews and audits.

COLLECT · ASSIGN · REVIEW · DOCUMENT

How does an issued key become an accountable inventory?

The reachable YubiKey is inspected during an appropriate lifecycle operation. The central view connects device inventory with identities and company policies. The portal presents the recorded state; a disconnected key supplies no new data.

  1. 01

    Collect during an operational workflow

    Certificate replacement, FIDO2 provisioning or an administrative inspection provides the occasion for inventory collection. The key must be reachable through the connection supported for that operation.

  2. 02

    Connect the device, identities and services

    SYNRION x.ID associates the physical key with its users and identities. PIV certificates and discoverable FIDO2 credentials remain identifiable as different inventory components.

  3. 03

    Provide the appropriate portal view

    Employees receive their personal view. Authorized company administrators inspect the central inventory and associated lifecycle operations. Visibility follows the applicable permissions.

  4. 04

    Review policies and document actions

    Company policies provide the basis for assignments, permitted use and inventory reviews. Recorded operations help establish what was collected, changed or inspected.

THE ARCHITECTURE AT A GLANCE

A shared inventory connects personal visibility, central oversight and lifecycle evidence.

One YubiKey with PIV certificates and FIDO2 passkeys connects multiple identities to employee and company views in the SYNRION x.ID portal; collection, review and evidence form the workflow.
A shared inventory connects personal visibility, central oversight and lifecycle evidence. Open full-size diagram ↗

TECHNICAL DEPTH

What the inventory captures—and what firmware 5.8 enables.

Central PIV management is already available. The extension arriving at it-sa 2026 adds repeated inventory of discoverable FIDO2 credentials. Firmware requirements, readable data and product capabilities have distinct roles.

PIV certificates and identities
The x.ID inventory connects certificate, issuer, PIV slot, identity and lifecycle. Microsoft Entra ID and local Active Directory can be integrated into the managed identity context.
Stored FIDO2 passkeys
The extension inventories FIDO2 credentials discoverable on the YubiKey, their associated services and the account information provided. It shows which stored passkeys belong to the inspected key. Non-discoverable registrations cannot be turned into a complete list of online accounts.
Usage and remaining capacity
The number of existing discoverable FIDO2 credentials and the key’s estimated remaining capacity support inventory planning. Private authentication keys are not collected as inventory data.
YubiKey firmware 5.8 or later
The repeated FIDO2 inventory described here requires supported YubiKeys with firmware 5.8 or later. This requirement applies to the new capability; existing central PIV management has its own hardware approvals.
Agentless* browser-based management
*No SYNRION agent installation on the user’s computer in supported jump-host deployments. A centrally deployed component handles device access. Employees and authorized administrators use the web portal.
Recorded inventory and effective access
A credential’s presence does not alone prove that its service still accepts authentication. Reviews therefore consider device inventory, assignments and recorded operations in context. Inventory collection alone is not revocation.

EVIDENCE & BOUNDARIES

One company view for operations, policies and audit.

The shared PIV and FIDO2 inventory view is part of the x.ID feature release for it-sa 2026. It extends the existing PIV lifecycle with central visibility into stored FIDO2 passkeys and their assignments.

Employees and the organization

Two authorized perspectives on the same managed context: personal keys and identities in the portal, and a central overview for the responsible company roles.

Evidence within the lifecycle

Recorded inventory, assignments and operations help explain inspections and changes. The shared SYNRION base module provides reports and authorized analysis.

Read about hardware requirements

THE NEXT CONTROLLED STEP

See your YubiKey inventory from both perspectives.

Meet us at it-sa 2026 to discuss the personal portal, company overview and your policies for PIV certificates and FIDO2 passkeys.

Arrange a meeting at it-sa