Using a YubiKey Hard Token to Authenticate with MFA

The hard token is an alternative method for those who are unable to use the Authenticator app or other phone options for multi-factor authentication. To get started, purchase a YubiKey hard token device from the Tech Store.

Students without a smartphone or the ability to receive text messages should create a ticket to avoid being locked out of your UARK account while waiting to receive your hard token device. 

How It Works

Once you have completed the setup steps, the YubiKey hard token device is inserted into your computer's USB drive. With the token plugged into your computer, it will automatically verify your account when logging into a UARK online service from that computer.

If you use multiple computers, you must have your YubiKey with you to use with the other computers. The Yubico Authenticator application must be installed on any computer you use to log into UARK online services.

How to Purchase a Hard Token

The university standard for hard token devices is the YubiKey provided by Yubico. These can be purchased through the University of Arkansas Tech Store by contacting Jeff Blevins at blevins@uark.edu with the YubiKey model needed for your device.  

The following YubiKey models are supported by IT Services:  

YubiKey 5 NFC (USB-A)

YubiKey 5 NFC (USB-A)

This is the standard-sized token, compatible with most Windows computers.

YubiKey 5Nano (USB-A)

YubiKey 5Nano (USB-A)

This is a smaller-sized token, compatible with most Windows computers.

YubiKey 5Ci (USB-C and Lightning)

YubiKey 5Ci (USB-C and Lightning)

This token is recommended for Mac computers.

YubiKey Hard Token Setup

The YubiKey hard token plugs into your computer and verifies your UARK account for multi-factor authentication. The university recommends installing the YubiKey Authenticator app on any device you will use with the hard token. 

In order to download the application, you must have administrator access on your computer. If you are prompted for an administrator password, please contact your department's tech support person. 

  1. On your primary work or school computer, download and install the Yubico Authenticator app:
  2. Once installed, open Yubico Authenticator, and insert the YubiKey hard token into the USB port.
  3. Click Add Account or "+" to add your UARK account. 
  4. Open the computer's web browser and go to account.uark.edu.
  5. Click Edit security info on the right, under Manage account.
  6. Click +Add method and select Authenticator app.
  7. Click the "I want to use a different authenticator app" link. Click Next.
  8. On the screen showing a QR code, click the "Can't scan image" link.
  9. Your UARK email address will appear with a Secret key. Click the Copy icon next to the Secret key to copy it to your clipboard.
  10. In the Yubico Authenticator window, click Scan.
    If you get an error, click Manual. 
  11. Verify that the Issuer is listed as Microsoft and your UARK account is correct. Click Add.
    If the information on this screen is incorrect or missing:
    1. Enter Microsoft in the Issuer field.
    2. Enter your UARK email address in the Account name field.
    3. Paste your Secret key. 
    4. Leave the Require touch check box unchecked.
    5. Click Add.
  12. Return to the web browser window with the Authenticator app information. Click Next.
  13. Under Enter code, provide the six-digit code displayed in the Yubico Authenticator application. Click Next.
  14. On the Security info screen in your web browser, make sure the Default sign-in method is set to "Authenticator app or hardware token - code."
    Note: If this is not correct, click the Change link, and select "Authenticator app or hardware token - code" from the dropdown menu. Click Confirm.
  15. Click the My Account profile icon at the top right of the window, and select Sign Out.

For assistance setting up multi-factor authentication, submit a ticket.

Print Article

Details

Article ID: 172
Created
Sat 1/27/24 3:21 PM
Modified
Mon 8/12/24 4:43 PM

Related Articles (3)

Your MFA authentication method can be changed.
Multi-factor authentication (MFA) is required for all student, faculty, and staff UARK accounts. After activating your UARK account, register for MFA.
The easiest and most secure method for multi-factor authentication (MFA) is the Microsoft Authenticator app.