Yes—Windows App on iPhone and iPad can preview-redirection of a compatible YubiKey’s smart-card (CCID/PIV) interface into a Windows 365 Cloud PC. The key must be physically connected before the remote session starts; NFC is not supported. Microsoft currently labels the capability preview, and it is not generic USB, FIDO2, passkey, OTP or NFC passthrough.
The feature first appeared in Windows App 11.0.4. Microsoft’s current support table and limitations are documented at Windows App device and resource redirection.
What the feature actually does
The supported flow is:
- Connect a compatible YubiKey to an iPhone or iPad.
- Start Windows App and connect to a Windows 365 Cloud PC.
- Windows App redirects the YubiKey’s smart-card/CCID interface through RDP.
- Windows inside the Cloud PC detects the card and can use its PIV certificate in a smart-card-aware application or website.
This is different from signing in to Windows App, authenticating to Entra ID with a passkey, using Yubico Authenticator locally on iOS, or passing through every YubiKey protocol. FIDO2, OTP, HID and proprietary USB functions are not implied by smart-card redirection.
Windows 365, Azure Virtual Desktop and Dev Box
Microsoft’s smart-card redirection guidance covers Windows 365, Azure Virtual Desktop and Microsoft Dev Box because they use the same underlying RDP behavior. This article focuses on Windows 365:
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
- Windows 365: configure the Cloud PC through Intune or Group Policy.
- Azure Virtual Desktop: configure the session host through Intune or Group Policy, with optional host-pool RDP controls.
- Dev Box: configure the dev-box operating system through Intune or Group Policy.
Supported keys and prerequisites
Microsoft describes support for the latest YubiKey 5 portfolio. Do not assume that every historic YubiKey, Security Key or third-party smart card is supported. Confirm the exact model, connector, firmware and organizational requirements with Microsoft or Yubico. Yubico’s product references include the YubiKey 5 Series, YubiKey 5Ci and YubiKey 5C NFC.
- A provisioned Windows 365 Cloud PC.
- Windows App installed on a supported iPhone or iPad.
- A compatible YubiKey 5 device with a PIV certificate, PIN and usable private key.
- A physical connector connection; NFC does not work for this feature.
- Cloud PC policy that permits smart-card redirection.
- Intune or Group Policy rights to configure the computers providing the remote session.
- A target application or website that supports Windows smart-card/PIV authentication.
- A trusted certificate chain, valid certificate and service-side certificate mapping where required.
No YubiKey driver installation is required on the iPhone or iPad for this preview integration. Intune administrators need the Policy and Profile Manager role and a group containing the computers that provide the remote session.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Enable smart-card redirection in Windows 365
Windows 365 enables smart-card redirection at the service layer unless an operating-system policy blocks it. The most restrictive applicable setting wins.
Intune
- Sign in to the Microsoft Intune admin center.
- Create or edit a configuration profile for Windows 10 and later devices.
- Choose the Settings catalog profile type.
- Browse to Administrative Templates → Windows Components → Remote Desktop Services → Remote Desktop Session Host → Device and Resource Redirection.
- Select Do not allow smart card device redirection.
- Set it to Disabled to allow redirection. Enabled blocks it; Not configured generally allows it unless another policy blocks it.
- Assign the profile to the group containing the Cloud PC computers, then create or deploy it.
- Restart affected Cloud PCs after the policy applies.
Group Policy
- Open Group Policy Management and create or edit a policy targeting the Cloud PC operating-system environment.
- Go to Computer Configuration → Policies → Administrative Templates → Windows Components → Remote Desktop Services → Remote Desktop Session Host → Device and Resource Redirection.
- Open Do not allow smart card device redirection.
- Choose Disabled or Not configured to permit redirection; choose Enabled to block it.
- Apply the policy and restart the Cloud PC.
Because the policy name is negative, setting it to Enabled has the opposite effect of what many administrators first expect.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Connect from an iPhone or iPad
- Physically insert the YubiKey into the iPhone or iPad. Use a model and connector compatible with that device, or an Apple-approved adapter arrangement.
- Open Windows App.
- Start the Windows 365 connection only after the key is connected.
- Sign in to the Cloud PC.
- Open the certificate-aware application or website and select the PIV certificate when prompted.
The iOS/iPadOS redirection table lists YubiKey smart card (preview), but it is not exposed as an ordinary per-device toggle like microphone, camera, clipboard or storage. If the key is inserted after the session begins, disconnect Windows App and reconnect with the key already attached.
Verify the redirected card
Inside the Cloud PC, open Command Prompt or PowerShell and run:
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
certutil -scinfo
A working session should show the Smart Card Resource Manager and a reader similar to Yubico YubiKey OTP+FIDO+CCID 0. A PIV setup may identify the card as Identity Device (NIST SP 800-73 [PIV]). Then test the real application or website. The command proves that Windows can see the reader; it does not prove that the certificate is trusted, the PIN is correct or the target service accepts the certificate.
What “login” means here
There are three separate authentication events:
- Windows App sign-in: authentication to Windows App or the Windows 365 service.
- Cloud PC sign-in: authentication to Windows running in the Cloud PC.
- Application sign-in: certificate-based authentication inside the Cloud PC using the redirected PIV card.
Smart-card redirection primarily addresses the third event. It does not automatically replace every Windows 365 password, Entra ID, FIDO2 or passkey sign-in flow. Microsoft documents FIDO devices and passkeys separately in its Azure Virtual Desktop and Windows 365 updates.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsBest Value
- The information below is per-pack only
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
Troubleshooting matrix
| Symptom | Likely cause | Action |
|---|---|---|
| No YubiKey reader in the Cloud PC | Inserted after session start, blocked policy, unsupported client or physical connection issue | Disconnect and reconnect with the key attached; check Intune/GPO and client support. |
| NFC tap does nothing | NFC is unsupported for this redirection path | Use a physically connected compatible key. |
certutil -scinfo finds no reader |
Redirection is blocked or the device was not enumerated | Review effective policy, restart after policy application, reconnect the key and retest. |
| Reader appears but certificate login fails | Missing, expired or untrusted certificate; wrong PIN; certificate mapping or application incompatibility | Inspect the PIV certificate and trust chain, verify the PIN and test a known smart-card-aware application. |
| Policy looks correct but access remains unavailable | A more restrictive policy applies elsewhere | Review effective computer policy; the most restrictive setting wins. |
| Works on one iPad but not another | Different connector, iOS/iPadOS version, Windows App version, hardware or management profile | Compare those variables and the YubiKey model. |
| Browser or application cannot use the key | The software may not support Windows smart-card APIs or PIV | Test a known certificate-aware application; do not assume FIDO or OTP compatibility. |
Security and operational considerations
- Preview risk: Microsoft still labels the iOS/iPadOS capability preview. Test client updates and maintain a fallback before making it the sole authentication path for critical work.
- Credential exposure: Redirection lets a remote session use a hardware-held credential. Restrict the policy to approved users and Cloud PCs, and define lost-key, certificate-revocation and PIN procedures.
- Connector choice: NFC-equipped keys do not gain NFC functionality in this scenario. USB-C models suit USB-C iPhones and iPads; the 5Ci provides USB-C and Lightning connectors.
- Application compatibility: A visible card is not universal protocol passthrough. The application must support Windows smart-card/PIV authentication.
For a USB-C iPhone or iPad, compare connector-matched YubiKey 5 models; for a Lightning device, the YubiKey 5Ci is the directly relevant form factor. Check current availability and organizational compliance requirements on Yubico’s support page before procurement. Microsoft directs integration-support questions to Yubico Support Services.
Frequently Asked Questions
Can I use NFC instead of plugging in the YubiKey?
No. Microsoft explicitly excludes NFC for the Windows App iOS/iPadOS smart-card redirection feature; the key must be physically connected before the session starts.
Does the iPhone need a YubiKey driver?
No driver installation is required on the iPhone or iPad for this preview integration.
What command confirms detection in the Cloud PC?
Run certutil -scinfo. It should list the Smart Card Resource Manager and a Yubico CCID reader, but application authentication still requires a valid, trusted PIV certificate and compatible software.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchDoes this make the YubiKey a universal Windows 365 passwordless login device?
No. It redirects the smart-card/PIV interface for supported applications. Windows App sign-in, Cloud PC sign-in and FIDO2/passkey authentication are separate flows.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




