YUBIKEY LIFECYCLE MANAGEMENT

One security key. Multiple identities and use cases. One controlled lifecycle.

SYNRION x.ID connects authentic hardware, the accountable person, PIV and FIDO2 credentials, policies and recovery. Every state remains visible from preparation to retirement.

VALUE IN 30 SECONDS

The complete lifecycle in 30 seconds.

01

Know the hardware

Attestation and inventory connect a real security key to its model, capabilities and controlled state.

02

Know the identity

A primary identity remains accountable for every secondary identity, certificate, role and FIDO2 credential.

03

Control every change

Issue, renew, revoke, replace and retire through policy-driven steps that remain traceable.

FROM PREPARATION TO RETIREMENT

What must remain connected throughout a YubiKey lifecycle?

The key itself is only one part of the process. Reliable lifecycle management joins hardware proof, identity assignment, credentials, policy and recovery into one operating model.

  1. 01

    Register authentic hardware

    Record the security key before or during issue and verify the available hardware evidence instead of treating every USB device as equivalent.

  2. 02

    Bind the accountable identity

    Assign the key to a verified primary identity and preserve that relationship when additional roles or secondary identities are added.

  3. 03

    Provision PIV and FIDO2 use cases

    Prepare Windows and Linux certificate authentication, FIDO2 and passkey scenarios from one controlled portal and keep each credential connected to its intended use.

  4. 04

    Enforce policy before trust is granted

    Check identity, hardware and independent approval rules together. A technically enforced four-eyes principle can become part of the decision.

  5. 05

    Operate, renew and change safely

    See which credentials are active, renew them in time and change roles without losing the relationship to the person, key and policy.

  6. 06

    Revoke, replace and retire

    When a key is lost, damaged or no longer required, remove trust deliberately, issue controlled replacement hardware and preserve the audit trail.

THE ARCHITECTURE AT A GLANCE

On-premises Active Directory and Microsoft Entra ID are part of the lifecycle from day one: the certificate, strong SKI mapping, FIDO2 registration and hardware state change under the same control.

Lifecycle diagram showing YubiKey registration, attestation, Active Directory through the LDAP Connector, Microsoft Entra ID through the native Azure Connector, PIV and FIDO2 provisioning, recovery and retirement.
On-premises Active Directory and Microsoft Entra ID are part of the lifecycle from day one: the certificate, strong SKI mapping, FIDO2 registration and hardware state change under the same control.

TECHNICAL DEPTH

The terms behind the lifecycle.

These concepts describe different proofs and must not be collapsed into a single “key is present” signal.

PIV attestation
A signed attestation statement can show that a supported PIV key pair was generated by the hardware and can bind technical evidence to the issuing device. It complements identity verification; it does not replace it.
FIDO2 and passkeys
FIDO2 provides phishing-resistant authentication based on public-key credentials. The credential lifecycle and device assignment still need controlled registration, issue, loss response and retirement.
Primary and secondary identities
The primary identity identifies the accountable person. Secondary identities represent additional roles or contexts and remain connected to that person instead of becoming unmanaged parallel accounts.
Policy enforcement
Independent rules decide whether the available identity, hardware and approval evidence is sufficient. This makes separation of duties and a technical four-eyes principle enforceable.
Active Directory: certificate and strong mapping
The LDAP Connector can publish the issued certificate to userCertificate and maintain a strong X509: mapping in altSecurityIdentities. The optional Microsoft SID extension in the certificate provides another strong Microsoft mapping path.
Microsoft Entra ID: native Azure Connector
The Azure Connector addresses Microsoft Entra ID directly. It joins the x.ID lifecycle to Microsoft Graph processes for FIDO2/passkey preregistration and, for Entra CBA, to certificateUserIds for an SKI-based high-affinity binding.

EVIDENCE & BOUNDARIES

What SYNRION x.ID makes verifiable.

The value is not a list of credentials. It is the persistent relationship between hardware, identity, intended use, policy and current lifecycle state.

Available

Clear assignment

The security key, primary identity, secondary identities and applications remain visibly related.

Available

Controlled state changes

Issue, renewal, blocking, replacement and retirement follow explicit lifecycle actions.

Available

Integrable operating model

On-premises Active Directory and Microsoft Entra ID use separate LDAP and Azure Connector paths; certification authorities and external systems can be added.

View the official Works with YubiKey entry

THE NEXT CONTROLLED STEP

See your existing YubiKey process as one lifecycle.

We will show how procurement, assignment, PIV, FIDO2, policy, recovery and retirement fit into your current identity and PKI environment.

Request an x.ID demo