Enroll a U-M Hardware Token or U-M YubiKey for Duo

Environment

University of Michigan, U-M Hardware Token, or U-M YubiKey

Issue

Instructions for enrolling a U-M hardware token or U-M YubiKey in Duo so you can use it for two-factor authentication (2FA) at U-M.

Resolution

  1. From a desktop or laptop computer, go to UMICH Account Management.
  2. Log in with your uniqname and UMICH password.
  3. Click Add a Duo Hardware Token or Yubikey.
  4. Select the Token Type.
  5. Enter the serial number from the back of your U-M hardware token or U-M YubiKey in the Token Serial Number box.
  6. Click Enroll.

Additional Information

  • This applies to Duo only. Look for Okta specific knowledge for relevant Yubikey or hardware token  steps. 
  • You can have more than one hardware token or security key enrolled on your account.
  • With multiple hardware tokens enrolled, the Universal Prompt will have a single 'Hardware token' option that accepts a passcode from any of your enrolled token.
  • You can only add a Duo hardware token/YubiKey when navigating to UMICH Account Management, not Duo Account Management.
  • You can remove a Duo hardware token/YubiKey when navigating to UMICH Account Management or Duo Account Management.

Note: U-M is moving to Okta on Feb 25, 2026. Yubikeys can also be used with Okta. See Enroll a YubiKey (Security Key) for Okta Multi-Factor Authentication for instructions on enrolling your Yubikey in Okta as an additional MFA option.

Need additional information or assistance? Contact the ITS Service Center.

Print Article

Related Articles (3)

This document describes the options available with Duo for two-factor authentication and includes links to enrollment instructions for each option.