Enable YubiKey OTP authentication (2024)

This topic describes how to configure a YubiKey one-time password (OTP) in your tenant so you can select it as an authentication mechanism when creating an authentication profile.

YubiKey OTP generates an OTP as a second authentication factor to provide a second layer of security without using a memorized secret. CyberArk Identity supports YubiKey OTPas an authentication mechanism that you can use for other applications.

Before you begin

Complete the following before you begin
Task Description

Set up YubiKey using the YubiKey Manager to configure the two slots on your YubiKey operating system.

See YubiKey Manager for more information.

Obtain your YubiKey APIcredentials.

The following information is available from Yubico APIkey signup:

  • Client ID

  • Secret Key

Configure YubiKey in the Identity Administration portal

  1. Go to Settings > Authentication > YubiKey Configuration, then select Enable YubiKey OTP.

  2. Enter the client ID and secret key in the appropriate fields. This information is available in your YubiKey setup.

  3. Select the period of time that the challenge response will time out using the Timeout drop-down menu. You can choose from 10 to 60 seconds in increments of 10 seconds.

  4. You can select Allow unrecognized YubiKeys to register to allow users to register a key that has not been added in the Registered YubiKey users table in the User Portal. This is unselected by default.

    (Optional) You can populate the table if Allow unrecognized YubiKeys to register is unselected to allow other devices to enroll.

  5. Click Save.

Set the policy to use with YubiKey OTP

The following procedure describes how to enable enrollment of YubiKey OTP and how to select it as an authentication mechanism.

  1. Go to Core Services > Policies to select the policy you want to use.

  2. In the policy, go to User Security Policies > User Account Settings and select Yes next to Enable users to configure a YubiKey OTP device.

    (Optional) You can select Yes next to Prompt users to configure a YubiKey OTP on login to enable a wizard.

  3. You can use the authentication profile required to configure the YubiKey OTP drop-down menu. See create an authentication profile for more information.

  4. Click Save.

Add YubiKey devices

  1. Go to Settings > Authentication > YubiKey Configuration and click Add.

    (Optional) Select the username for the key.

  2. Enter the YubiKey ID.

    Ensure that the Active checkbox is selected.

  3. Click Add.

    The key is ready for the user.

Edit registered YubiKey users

You can modify, delete and deactivate registered YubiKey users in the table.

  1. Select the checkbox for the registered user in the table.

  2. Click Actions to modify, delete and deactivate.

Set up OTPs to authenticate to the User Portal

Import YubiKey OTP tokens in bulk

Create authentication profiles

Enable YubiKey OTP authentication (2024)
Top Articles
What are the best browsers for Web 3.0?
Is Meta Stock A Buy? Facebook Parent's Shares Test Key Level
Skigebiet Portillo - Skiurlaub - Skifahren - Testberichte
Star Wars Mongol Heleer
My E Chart Elliot
What Are Romance Scams and How to Avoid Them
Usborne Links
Google Sites Classroom 6X
Find All Subdomains
Jesus Revolution Showtimes Near Chisholm Trail 8
Urinevlekken verwijderen: De meest effectieve methoden - Puurlv
The Wicked Lady | Rotten Tomatoes
LeBron James comes out on fire, scores first 16 points for Cavaliers in Game 2 vs. Pacers
FAQ: Pressure-Treated Wood
Where does insurance expense go in accounting?
Dump Trucks in Netherlands for sale - used and new - TrucksNL
Darksteel Plate Deepwoken
Dr. med. Uta Krieg-Oehme - Lesen Sie Erfahrungsberichte und vereinbaren Sie einen Termin
Maplestar Kemono
Apus.edu Login
St Maries Idaho Craigslist
Hobby Stores Near Me Now
Is Windbound Multiplayer
Governor Brown Signs Legislation Supporting California Legislative Women's Caucus Priorities
Gazette Obituary Colorado Springs
Imouto Wa Gal Kawaii - Episode 2
Paris Immobilier - craigslist
Craigslist Rentals Coquille Oregon
manhattan cars & trucks - by owner - craigslist
This Is How We Roll (Remix) - Florida Georgia Line, Jason Derulo, Luke Bryan - NhacCuaTui
Sinfuldeed Leaked
Airg Com Chat
Trust/Family Bank Contingency Plan
Grove City Craigslist Pets
Song That Goes Yeah Yeah Yeah Yeah Sounds Like Mgmt
Appraisalport Com Dashboard /# Orders
Nacho Libre Baptized Gif
School Tool / School Tool Parent Portal
Mydocbill.com/Mr
Tirage Rapid Georgia
NHL training camps open with Swayman's status with the Bruins among the many questions
Noaa Marine Weather Forecast By Zone
All Obituaries | Sneath Strilchuk Funeral Services | Funeral Home Roblin Dauphin Ste Rose McCreary MB
Craigslist Rooms For Rent In San Fernando Valley
Phone Store On 91St Brown Deer
5103 Liberty Ave, North Bergen, NJ 07047 - MLS 240018284 - Coldwell Banker
Laura Houston Wbap
Ty Glass Sentenced
Unit 4 + 2 - Concrete and Clay: The Complete Recordings 1964-1969 - Album Review
How to Find Mugshots: 11 Steps (with Pictures) - wikiHow
Adams County 911 Live Incident
Land of Samurai: One Piece’s Wano Kuni Arc Explained
Latest Posts
Article information

Author: Clemencia Bogisich Ret

Last Updated:

Views: 6035

Rating: 5 / 5 (80 voted)

Reviews: 95% of readers found this page helpful

Author information

Name: Clemencia Bogisich Ret

Birthday: 2001-07-17

Address: Suite 794 53887 Geri Spring, West Cristentown, KY 54855

Phone: +5934435460663

Job: Central Hospitality Director

Hobby: Yoga, Electronics, Rafting, Lockpicking, Inline skating, Puzzles, scrapbook

Introduction: My name is Clemencia Bogisich Ret, I am a super, outstanding, graceful, friendly, vast, comfortable, agreeable person who loves writing and wants to share my knowledge and understanding with you.