Enroll a U-M Hardware Token or U-M YubiKey for Duo

Summary

This document provides instructions for enrolling U-M hardware tokens and U-M YubiKeys.

Body

Environment

University of Michigan, U-M Hardware Token, or U-M YubiKey

Issue

Instructions for enrolling a U-M hardware token or U-M YubiKey in Duo so you can use it for two-factor authentication (2FA) at U-M.

Resolution

  1. From a desktop or laptop computer, go to UMICH Account Management.
  2. Log in with your uniqname and UMICH password.
  3. Click Add a Duo Hardware Token or Yubikey.
  4. Select the Token Type.
  5. Enter the serial number from the back of your U-M hardware token or U-M YubiKey in the Token Serial Number box.
  6. Click Enroll.

Additional Information

  • This applies to Duo only. Look for Okta specific knowledge for relevant Yubikey or hardware token  steps. 
  • You can have more than one hardware token or security key enrolled on your account.
  • With multiple hardware tokens enrolled, the Universal Prompt will have a single 'Hardware token' option that accepts a passcode from any of your enrolled token.
  • You can only add a Duo hardware token/YubiKey when navigating to UMICH Account Management, not Duo Account Management.
  • You can remove a Duo hardware token/YubiKey when navigating to UMICH Account Management or Duo Account Management.

Note: U-M is moving to Okta on Feb 25, 2026. Yubikeys can also be used with Okta. See Enroll a YubiKey (Security Key) for Okta Multi-Factor Authentication for instructions on enrolling your Yubikey in Okta as an additional MFA option.

Need additional information or assistance? Contact the ITS Service Center.

Details

Details

Article ID: 11078
Created
Thu 10/26/23 2:04 PM
Modified
Fri 1/23/26 11:25 AM

Related Articles

Related Articles (3)

This document describes the options available with Duo for two-factor authentication and includes links to enrollment instructions for each option.