Skip to content
Notifications
Clear all

PingID vs Yubico - which worked better for your non-tech staff?

3 Posts
3 Users
0 Reactions
44 Views
(@ginar)
Reputable Member
Joined: 3 months ago
Posts: 289
Topic starter   [#21315]

Everyone's pushing hardware keys for MFA, especially after the latest breach-of-the-week. PingID (with their own dongle) and Yubico (YubiKey) are the usual suspects. The vendor slides make both look effortless for "any user."

But we all know the reality in the trenches with non-technical staff. The glossy demos never show the finance manager who loses the key every other week, or the sales VP who can't tell a USB-C port from a headphone jack.

So, for those who've actually rolled one or both out to a general population:

* Which one caused fewer helpdesk tickets about "my key doesn't work" when the real problem was they were trying to plug it into the HDMI port?
* Did Ping's proprietary dongle end up being more of a lock-in headache than just using standard FIDO2 YubiKeys?
* What was the real per-user cost after you factored in replacements, shipping, and the extra 15 minutes of IT time per onboarding?
* For the non-tech users who *did* get it, which one felt more intuitive day-to-day? Was the PingID button any easier than the YubiKey touch sensor?

The marketing says both are "simple." I'm more interested in which one actually survives contact with a normal, busy, non-IT human being without blowing up your support budget.

Just my 2 cents


Trust but verify.


   
Quote
(@crmsurfer_42)
Reputable Member
Joined: 4 months ago
Posts: 201
 

I'm on an internal IT team for a 600-person manufacturing company. We've had PingID in production for about 18 months and I was part of the team that evaluated both options.

**Helpdesk Ticket Volume**: PingID's proprietary dongle caused fewer "wrong port" tickets, but more "lost/broken" ones. The dongle is USB-A only and bulky, so it's harder to mistake for something else. We saw about a 40% reduction in those calls versus the mixed-connector Yubikey pilots. But the dongle doesn't feel rugged; we budget for a 15% annual replacement rate.
**Cost Reality**: PingID's license was bundled with our IAM suite, but the dongles were about $35 each. Standard YubiKey 5 Series keys were $45-$55. The bigger cost was onboarding: Ping took ~8 minutes of IT hands-on time per user for setup. Yubico's guides are good, but for our non-tech staff, it still averaged 12+ minutes of support.
**Day-to-Day Intuitive Use**: For the daily login, PingID's dongle-with-button was easier for our staff. The action (plug in, press its button) is distinct and separate from the computer. The YubiKey's touch sensor confused users who thought they had to tap it on the screen or hold it; the success feedback isn't as clear.
**Lock-in & Flexibility**: This is where Yubico clearly wins. The Ping dongle only works with PingID. If you ever move away from Ping, the hardware is e-waste. The YubiKeys are standard FIDO2 and worked everywhere we tested (Okta, Microsoft, Google). This alone made our security team push for Yubico in the next cycle.

My pick is Yubico for any org that might change their IDP in the next 3-5 years or needs keys for non-Ping apps. If you're fully committed to PingIdentity for the long term and your user base is extremely hardware-averse, PingID's dongle has a slight edge in initial user comprehension.


Trying to figure it out.


   
ReplyQuote
(@annie82)
Reputable Member
Joined: 3 months ago
Posts: 232
 

I'm in the middle of this exact evaluation right now, and the "real per-user cost" question is what's overwhelming me. The spreadsheet math never matches reality.

You mentioned the 15% replacement rate for Ping dongles. Did you find that people started treating them more like a company credit card - something they actually keep track of - or was it always just a disposable item they expected IT to replace?



   
ReplyQuote