Setup a Yubikey as an MFA Passkey

This walk through shows how to configure a Yubikey MFA for SVC's Okta Identity Provider.

  • The steps differed slightly between browsers, so both Chrome and the recommended Edge are represented within the steps.
    • The main points of interest are addressed within the walk-through to configure the hardware passkey, and any differing steps not represented should be minimal and easily addressed by following the system prompts.
  • The walk-through should provide benefit for any combination of Identity Provider and passkeys; the basic steps of adding an MFA method are. 

 

Please contact the Information Technology Help Desk if you have any questions about these steps. 

 

Note: Do not connect the passkey to your computer at this time. 

  1. Open a web browser and navigate to skagit.okta.com
     For Microsoft MFA, sign in to https://mysignins.microsoft.com/security-info with your SVC email account
      or https://myaccount.microsoft.com if that direct link stops working, selecting My Account  and then Security Info from the left hand menu,
      then continue below at step 6.

     
  2. Sign in to Okta with your Skagit Valley College account
     
  3. Click your name in the top right hand corner of the Okta App Landing page and select Account settings
    Decretive image describing the step

     
  4. You will be asked to authenticate with an MFA method if you have not done so recently; Authenticate with any offered Okta MFA method
    Decretive image describing the step

     
  5. Scroll down to the Security Methods card on the Account settings page 
     
  6. Click the Set up button for Security Key or Biometric Authenticator
    NOTE: Okta changed the method to "Passkey" after this document was published, so expect to see "Passkey" in the place of "Security Key or Biometric Authenticator". The process is otherwise identical. 
    Decretive image describing the step

     
  7. Click the Set up button for Security key or biometric authenticator on the Set up security methods page
    Decretive image describing the step
    1. Note: One test produced a Set up button Google Authenticator rather than Security key or biometric authenticator; If you see any other authenticator method, try restarting this walk-through and use the Edge browser if necessary. Continue once you are offered the Set up button for Security key or biometric authenticator.
       
  8. Click the Set up button on the Set up a security key or biometric authenticator page
     
  9. Bypassing Web Browser Passkey Management; Web browsers will first offer their own software passkey; we will override this to select the option to provide a hardware passkey. While these browser based passkeys do provide exelent security, they are not the point of this walkhrough. 
    1. Chrome Example: If offered to create a passkey saved in your Gmail account to use accross devices, Do Not Click the Create button;
      Click the Save another way button, or similarly titled button/link, when offered to create the passkey with your Browser or Email identity
      Image with arrow pointing to the Save another way button, showing the create button crossed out, and underlining the note that the passkey will be saved to the Google Password Manager rather than the desired passkey
    2. Edge Example: If offered to save a Passkey to your Microsoft Password Manager for use accross devices, Do Not Click the Create button;
      Click the Save another way button, or similarly titled button/link.
      Image underlining "saved to Microsoft Password Manager", with a red ex crossing out the "Create" button and a green arrow pointed to "Save another way"

       
  10. Bypassing Windows Security Passkey Management; When Windows Security offers to save the passkey to your computer, Do Not Click the Continue button;
    Click the Change button when offered to create the passkey
    Image with an arrow pointing to the change button, showing the continue button crossed out, and an arrow pointing to the information icon that reveals the note that this was requested by Microsoft Edge to be saved to the computer rather than the desired Yubikey

     
  11. Click the Security Key option on the Choose where to save your passkey pop-up dialog
    Decretive image describing the step

     
  12. Follow the Windows Security prompts to insert the Yubikey passkey to continue
     
  13. Follow the Windows Security prompts to enter a Security Key PIN for the passkey, then click the OK button
    You will regularly enter this PIN when authenticating with the passkey
    Decretive image describing the step

     
  14. Follow the Windows Security prompts to touch the biometric scanner if present on your passkey
     
  15. Follow any other Windows Security prompts not covered within this document
     
  16. The Windows Security dialogs should close and Okta will show a banner in the bottom right hand side of the page indicating that you have successfully enrolled the security key 
    Decretive image describing the step
     
  17. You can confirm that the MFA method has been added to your Okta Account Settings Security Methods, where you can also remove that method
    Now would be an exellent time to remove insecure MFA methods such as phone and SMS in favor of the newly added passkey and the identity provider mobile phone app such as Okta Verify
    Decretive image describing the step