Yubikey Physical Hardware Instructions - Christian Brothers University (2024)

Overview

This guide was created to assist with adding a physical hardware token henceforth referred to as a “YubiKey” on the Microsoft Account as an authentication Method for Multi-Factor Authentication (MFA) in lieu of the Microsoft Authenticator app on a mobile device. This YubiKey must be removed if utilizing after the authentication process and kept on your person to ensure utmost security following its activation. It will be required to utilize the YubiKey every time you attempt to login to a Microsoft enabled MFA service (such as Outlook). If lost or stolen, report the incident to ITS immediately so proper action can be taken to remove the YubiKey method on your Microsoft Account.

Steps for Activation

Yubikey Physical Hardware Instructions - Christian Brothers University (1)

Step 1: Locate the “Yubico Authentication” program on the desktop machine. Generally, this will be available on the desktop via shortcut. In the event that the shortcut is not on the desktop, search for the program using the search function in the bottom left corner of the Windows 10 machine as you would any other program.

Step 2: Open the “Yubico Authentication” program. You will be instructed to insert your YubiKey. Insert the YubiKey into a free USB slot on your machine so the gold contact point is touching the physical lip inside the USB Slot. If entered correctly the Yubico Authenticator App will notify you that No Accounts Exist on your key during first-time setup.

(Note: If you insert the YubiKey backwards, where the contact point is not reaching the USB, the app will not detect the YubiKey. Try turning the YubiKey around or another USB slot).

Step 3: Click the Add button on the Yubico Authenticator app and you will be prompted “Scan” a QR code. This QR code is generated by Microsoft during the MFA additional method setup process discussed earlier in this document, but will be reviewed here as well.

Step 4: Navigate to the My Account preferences on your Microsoft account and select the “Security Info” > “Update Info” section prompts. From this selection, select the option that states “+ Add Method” where a drop-down menu will present multiple options, choose “Authenticator App”. Click “Add” then select the blue texts that states “I want to use a different Authenticator app.”

Yubikey Physical Hardware Instructions - Christian Brothers University (2)

Step 5: Click “Next” on the screen until you are prompted with a QR Code. Ensure the window is still open with the QR code and open the Yubico Authenticator App and hit “Scan”. The Yubico Authenticator App will automatically verify the QR code and list “Microsoft” as the “Issuer” and your email as the Account Name. Verify that the “Require Touch” selection is checked and hit “Add.”

See Also
Mobile

Step 6: Click “Next” on the window with the QR code and Microsoft will ask for a 6-digit Key to confirm to add the Authentication method. On the Yubico Authenticator App, your account will have 6 * above your account name, double click on the account to initiate touch, and lightly press on the gold circle on your YubiKey. A temporary 6-digit code will appear in the section previously marked by 6 * to enter into the requested area by Microsoft. Once entered, the Generic “Authenticator App” will appear as an option in your Microsoft account under “Security Info.”

You have successfully added YubiKey physical hardware token as an MFA authentication method.

Yubikey Physical Hardware Instructions - Christian Brothers University (3)

(Note: This temporary 6-digit code will time out after a short period and require you to repeat the steps and touch the YubiKey again to generate a new code. This code generation will be required every time you login to a Microsoft MFA enabled application.)

Troubleshooting

If your YubiKey is lost or stolen, immediately report the incident to ITS so proper action can be taken on the account, to ensure account security and access.

However, if you need to reset the account on your YubiKey for any reason, you can do so in the Yubico Authenticator Desktop Application while the YubiKey is plugged in.

To do so, click on the vertical ellipses in the top left corner to open the “Settings” menu. You can set an additional password for further security here, or utilize the “Reset” option to remove all accounts and set the YubiKey back to factory default settings.

Yubikey Physical Hardware Instructions - Christian Brothers University (4)

(Note: If this is done, your YubiKey will no longer provide access as an MFA option for your Microsoft account and must be re-setup with the instructions above).

Yubikey Physical Hardware Instructions - Christian Brothers University (2024)

FAQs

Does a YubiKey need to be plugged in all the time? ›

No, you only need to insert your yubikey when you are prompted to do so during login.

Where do I insert my YubiKey? ›

On a computer, insert the YubiKey into a USB-port and touch the YubiKey to verify you are human and not a remote hacker.

Why do you have to touch a YubiKey? ›

The access will be conditioned by a user physically triggering the touch sensor, which detracts malware issuing command on the Yubikey without user knowledge. The touch event is requested for up to 15 seconds, after which the Yubikey turns off the notification.

What is the lifespan of a YubiKey? ›

A Yubikey will essentially last forever, and if you stay clear of the insanity that is Passkeys its Webauthn element can support an infinite number of websites. Portability: I have a smartphone, a work laptop, a home laptop, and a home desktop. My Yubikey has USB and NFC, so it can trivially be used with all of them.

Does YubiKey work without Internet? ›

The YubiKey is crush-resistant and water-resistant. It requires no battery or cellular network connectivity and its simple touch authentication is four times faster than typing a One Time Password.

What if someone steals my YubiKey? ›

So, what happens if you lose your YubiKey? In that case, you can still use your Authenticator app (phew!). While you can't create a backup YubiKey, you can always contact Yubico to get a replacement key.

How do I use my YubiKey for the first time? ›

How to set up your YubiKey
  1. Plug in your YubiKey.
  2. Go to Yubico.com/setup and click your device.
  3. In the Compatible accounts and services section, browse the list of supported apps and services, and select the ones you want to secure with your device.
  4. Your selection will appear in a list next to the available apps.
Nov 27, 2023

Is YubiKey more secure than 2FA? ›

Another key advantage is its resistance to phishing attacks. Because the YubiKey communicates directly with the service it's securing, it's immune to counterfeit websites or other phishing schemes designed to capture 2FA codes.

How many passwords can YubiKey hold? ›

YubiKeys in the 5 Series can hold up to 25 resident keys.

How do I know if my YubiKey is working? ›

Testing the Credential
  1. Insert the YubiKey into the computer.
  2. Click the Yubico OTP button. The following screen, "Test your YubiKey with Yubico OTP" shows the cursor blinking in the Yubico OTP field.
  3. Tap the metal button or contact on the YubiKey. The OTP appears in the Yubico OTP field. ...
  4. Click Validate.
May 7, 2020

Do I need to eject my YubiKey? ›

2.6 The YubiKey does not need to be ejected to be removed, just pull it out of your device.

Does YubiKey require a PIN? ›

Many services suggest or require the use of a PIN. It is recommended that you set up a PIN before you add services to your YubiKey. The best way to do this is to use YubiKey Manager.

Why is my YubiKey not responding to touch? ›

YubiKeys utilize capacitive touch sensors, meaning that dry skin can make it harder for a touch to be recognized. Applying lotion to your skin may help with this issue. Additionally, applying more pressure when touching the sensor can ensure better coverage of your finger.

How do I get my YubiKey out of my laptop? ›

How can I safely remove my YubiKey? The YubiKey identifies as a USB keyboard to your PC, and does not need to be ejected when removed – you can just pull it out!

Can you unplug YubiKey? ›

The YubiKey identifies as a USB keyboard to your PC, and does not need to be ejected when removed – you can just pull it out!

Can YubiKey stop working? ›

Check to see if the YubiKey's LED is lit - if not, the YubiKey may not be receiving power. The issue may be as simple as the YubiKey is inserted upside down for USB-A connectors. Alternatively, the USB port may not be functioning correctly - if that is the case, try on a different USB port or computer.

How much power does a YubiKey draw? ›

The nominal power consumption of a Yubikey 2 is about 10mA at 5V, so this should be about 0.05W. If the power consumed in the Nano would in fact have been 8W, it would have been on fire for sure.

Top Articles
Latest Posts
Article information

Author: Domingo Moore

Last Updated:

Views: 5572

Rating: 4.2 / 5 (73 voted)

Reviews: 80% of readers found this page helpful

Author information

Name: Domingo Moore

Birthday: 1997-05-20

Address: 6485 Kohler Route, Antonioton, VT 77375-0299

Phone: +3213869077934

Job: Sales Analyst

Hobby: Kayaking, Roller skating, Cabaret, Rugby, Homebrewing, Creative writing, amateur radio

Introduction: My name is Domingo Moore, I am a attractive, gorgeous, funny, jolly, spotless, nice, fantastic person who loves writing and wants to share my knowledge and understanding with you.