Enroll a YubiKey (Security Key) for Okta Multi-Factor Authentication

Environment

University of Michigan, Multifactor Authentication

Issue

Instructions for obtaining and enrolling a YubiKey (Security Key) for Multifactor Authentication (MFA).

Resolution

Important Considerations:

  • For most users who wish to use a security key, an Okta hardware token is a better option as it offers more flexibility and is automatically enrolled for you at the time of purchase.
  • A YubiKey should only be used as an additional MFA device (the Okta Verify app is the recommended MFA method used in tandem with a YubiKey).
  • While a YubiKey can be enrolled and used in tandem with an Okta hardware token, it is not recommended based on current Okta support limitations.

Obtain a YubiKey

  • YubiKeys are available for purchase at the ITS Tech Shop (opens in new window) either online or in person (opens in new window). 
  • You can have multiple YubiKeys enrolled for Okta at the same time.

YubiKey Obtained Prior to January 14, 2026

  • YubiKeys obtained before January 14, 2026 that had been used with Duo can be migrated to Okta.

YubiKey Funding

  • The University will cover the cost of an initial YubiKey for each user (faculty including emeriti, staff, students, retirees, alumni, and sponsored affiliates). Shipping is not included. Please note: if you obtained a YubiKey via the Tech Shop before January 14, 2026, you will need to pay the full cost of the device if you're interested in ordering another YubiKey.

Add a YubiKey to Your Account

You can add a YubiKey to your account after you have completed initial enrollment with the Okta Verify App or an Okta Hardware token.

  1. Go to your Okta account settings
  2. Click Manage security methods.
  3. Click Set up or Set up Another next to “Security Key or Biometric Authenticator”.
  4. You will be prompted to enter your password and verify using your preferred method, if prompted.
  5. Click Security Key or Biometric Authenticator-Set Up.
  6. Click Set up.
  7. The exact steps for enrollment and authentication using Security Keys will vary depending on the operating system, browser, and security key model. Follow the guided enrollment steps to complete setup for your device.

Additional Information

  • If you use a password manager you may experience some variance from these instructions. 
  • YubiKey authentication using passcodes (OTP) are not yet supported with Okta.
  • The experience of setting up a Yubikey varies across operating systems and browsers.  ITS (SC and IAM) provides this general knowledge article but if you need additional assistance we recommend using another option (e.g., Okta Verify or an Okta hardware token).
  • As of February 2026, some users in Chrome are prompted for a PIN on their Yubikey that has not yet been established. Using Firefox as your browser may allow you to succeed.

Need additional information or assistance with Okta? Michigan Medicine affiliates, contact HITS. Other U-M affiliates, contact the ITS Service Center.