Setup a Yubikey as an MFA Passkey

This walk through shows how to configure a Yubikey MFA for SVC's Okta Identity Provider.

  • The steps differed slightly between browsers, so both Chrome and the recommended Edge are represented within the steps.
    • The main points of interest are addressed within the walk-through to configure the hardware passkey, and any differing steps not represented should be minimal and easily addressed by following the system prompts.
  • The walk-through should provide benefit for any combination of Identity Provider and passkeys; the basic steps of adding an MFA method are. 

 

Please contact the Information Technology Help Desk if you have any questions about these steps. 

 

Note: Do not connect the passkey to your computer at this time. 

  1. Open a web browser and navigate to skagit.okta.com
    Microsoft Edge on Windows will provide a streamlined experience, though you should be able to accomplish the steps on any OS and browser
     
  2. Sign in to Okta with your Skagit Valley College account
     
  3. Click your name in the top right hand corner of the Okta App Landing page and select Account settings
    Decretive image describing the step

     
  4. You will be asked to authenticate with an MFA method if you have not done so recently; Authenticate with any offered Okta MFA method
    Decretive image describing the step

     
  5. Scroll down to the Security Methods card on the Account settings page 
     
  6. Click the Set up button for Security Key or Biometric Authenticator
    Decretive image describing the step

     
  7. Click the Set up button for Security key or biometric authenticator on the Set up security methods page
    Decretive image describing the step
    1. Note: One test produced a Set up button Google Authenticator rather than Security key or biometric authenticator; If you see any other authenticator method, try restarting this walk-through and use the Edge browser if necessary. Continue once you are offered the Set up button for Security key or biometric authenticator.
       
  8. Click the Set up button on the Set up a security key or biometric authenticator page


    Note: Your web browser defaults to offering it's own software passkey; we will override this to select the option to provide a hardware passkey.
  9. Bypassing third party account and browser passkeys such as Gmail and Google Chrome
    If using the Edge browser, continue below at step 10
    1. If offered to create a passkey saved in your account to use accross devices, Do Not Click the Create button;
      Click the Save another way button, or similarly titled button/link, when offered to create the passkey with your Browser or Email identity
      Image with arrow pointing to the Save another way button, showing the create button crossed out, and underlining the note that the passkey will be saved to the Google Password Manager rather than the desired passkey

       
  10. When offered to create a passkey for your web browser saved to your computer, Do Not Click the Continue button;
    Click the Change button when offered to create the passkey
    Image with an arrow pointing to the change button, showing the continue button crossed out, and an arrow pointing to the information icon that reveals the note that this was requested by Microsoft Edge to be saved to the computer rather than the desired Yubikey

     
  11. Click the Security Key option on the Choose where to save your passkey pop-up dialog
    Decretive image describing the step

     
  12. Follow the Windows Security prompts to insert the Yubikey passkey to continue
     
  13. Follow the Windows Security prompts to enter a Security Key PIN for the passkey, then click the OK button
    You will regularly enter this PIN when authenticating with the passkey
    Decretive image describing the step

     
  14. Follow the Windows Security prompts to touch the biometric scanner if present on your passkey
     
  15. Follow any other Windows Security prompts not covered within this document
     
  16. The Windows Security dialogs should close and Okta will show a banner in the bottom right hand side of the page indicating that you have successfully enrolled the security key 
    Decretive image describing the step
     
  17. You can confirm that the MFA method has been added to your Okta Account Settings Security Methods, where you can also remove that method
    Now would be an exellent time to remove insecure MFA methods such as phone and SMS in favor of the newly added passkey and the identity provider mobile phone app such as Okta Verify
    Decretive image describing the step