Hyatt Hotels' YubiKey Success Story: Boosting Security, Efficiency & Guest Experience
International System Research Co., Ltd.
September 26, 2024
YubiKey Case Study
Hyatt Hotels
The YubiKey Implementation Story: Reducing Security Risks, Enhancing Operational Efficiency, and Improving Customer Experience
Challenges Faced by Hyatt Hotels
Hyatt Hotels had implemented Microsoft products such as Office 365 and Azure Active Directory (AD) Premium for ID/access management. They also used Multi-Factor Authentication (MFA) via SMS one-time passwords (OTP) for authenticating to systems like their reservation system and POS.
However, one-time password authentication is a prime target for phishing and Man-in-the-Middle (MiTM) attacks. In fact, investigations into security breaches experienced by Hyatt Hotels consistently traced back to erroneously approved Multi-Factor Authentication (MFA) requests, presenting a dangerous situation.
Customer experience and work efficiency were also affected. Staff had to use their mobile devices every time they needed to authenticate, which was time-consuming and caused frustration. Moreover, the sight of staff checking the devices also made them look like they were on social media, which was far from Hyatt Hotels' ideal.
YubiKey's Solution to the Challenges
YubiKey successfully resolved Hyatt Hotels' challenges.

System Integration
YubiKey's authentication standards support WebAuthn/FIDO2, FIDO U2F, One-Time Password (OTP), OpenPGP 3, and smart card authentication, allowing its use for authentication across a wide range of systems. Naturally, it also supports Azure AD authentication, clearing challenges related to system integration.

Achieving Passwordless Authentication and Enhancing Company-Wide Security
The YubiKey is a top-level security solution with strong phishing resistance. No matter how many social engineering or MFA fatigue attacks an attacker tries, they cannot access information without the YubiKey.
To enhance security across the company, YubiKeys are used not only by hotel staff, but also by call center staff and loyalty program staff who work in mobile device-restricted environments or remotely to access privileged access management (PAM) and Enterprise Resource Planning (ERP) systems.

Efficient Hotel Operations
YubiKey's passwordless authentication not only completes authentication up to four times faster than One-Time Passwords (OTP) or SMS authentication, but once authentication is complete, there's no need to re-authenticate until the session expires. This enabled both the front desk and call center to handle guest interactions securely and quickly.
Furthermore, with Azure AD and YubiKey, staff can sign on (log in) to necessary applications with passwordless authentication from the moment they join Hyatt Hotels.

Enhanced Customer Experience
As a result of achieving passwordless authentication with YubiKey, staff can increase eye contact with guests and provide a seamless customer experience. "What we are trying to create for our guests is an experience where there is nothing to interrupt the interaction between staff and guests," says Chernobrov, the person in charge.

Impressive Implementation Experience
Hyatt Hotels distributed YubiKey 5 NFC to their mobile front desk staff and 5C Nano to their call center and back office. While they anticipated inquiries from staff, there were absolutely no questions thanks to the explanatory videos and the excellent usability of YubiKey.
The Future of Hyatt Hotels
Hyatt Hotels' goal is to make all 200,000 staff across approximately 1,500 locations worldwide completely passwordless. To achieve this, they are deploying 5,000 to 10,000 YubiKeys with each new hardware introduction or application upgrade.
Achieving a fully passwordless environment incurs financial costs. However, Hyatt Hotels continues to invest to provide a safe and excellent experience for both guests and staff.



YubiKey Case Studies
YubiKey as a Service Case Study
YubiKey as a Service Case Study: Major Japanese Manufacturer Achieves Seamless Large-Scale Deployment

YubiKey Case Study
Medical IT Service Provider Adapta
Discover how Adapta delivers both fast and secure logins for healthcare professional with YubiKey.
Read Case Study