YubiKey: Windows setup instructions for multifactor authentication

Note: A Microsoft passkey is the designated MFA method for university faculty, staff, and students.

The YubiKey security key is an alternative MFA method for those who are unable to use passkey for multifactor authentication, such as those without the required phone OS or Bluetooth. After registration, your YubiKey can be used with multiple devices to log into university services. It is recommended that you purchase a second YubiKey as a backup in case your YubiKey is lost or damaged.

See About YubiKey and YubiKey FAQ for more information and troubleshooting.

Supported YubiKey models

The university standard for security keys is the YubiKey provided by Yubico. The following YubiKey models are supported by IT Services:  

Yubico YubiKey Security Key C NFC YubiKey 5C NFC
The C NFC model will be available to users for access to general university portals and systems, email, VPN, payroll and financial systems, research databases, and other data. The 5C NFC model is available to server administrators who are unable to use Duo. 

Step 1: Set up Windows Hello 

Note: Setting up Windows Hello is only for Windows devices. Mac users should use the YubiKey registration for Mac article to register their YubiKey. 

Instructions for setting up Windows Hello

Step 2: Request a YubiKey

If you are faculty, staff, or a student worker only, use the YubiKey Request form to request a YubiKey.

Step 3: Register your YubiKey 

NOTE: If the registration process times out, restart the registration process at “click +Add sign-in method”. Some steps may be skipped if you had already completed them before the time-out.

  1. Go to account.uark.edu.
    Note: You will be prompted to authenticate using the Authenticator app or a different method that has been set up on your account to register the YubiKey as a new MFA method.
  2. Under My Accounts, select Security Info.
  3. On the Security Info page, click +Add sign-in method.

    screenshot with Security info window with Add sign-in method link selected
     
  4. Add a sign-in method by selecting the Passkey option from the list.

    Add a sign-in method window with passkey indicated
     
  5. On the Sign in faster with your face, fingerprint, or PIN window, select Next.

    Sign in faster with your face, fingerprint, or PIN window with Next indicated
     
  6. Select Windows Hello or external security key when asked to choose where to save your passkey.

    Choose where to save your passkey window with Windows Hello or external security key option indicated
     
  7. When prompted by the Insert your security key into the USB port screen, plug the YubiKey into the device.

    screenshot of prompt to insert your security key into the USB port
     
  8. Create a PIN for the YubiKey. A YubiKey PIN can be 4-63 characters and may include letters, numbers, and special characters. Type the PIN in the New Security Key PIN field and again in the Confirm Security Key PIN field. Select OK when you are done creating the PIN.
    IMPORTANT: Don't share your PIN or choose an easy-to-guess number. Your PIN protects access to your device, passkeys, and other sensitive information, so it should be safeguarded just as carefully as a password.

    screenshot -- create a PIN for this security key with New Security Key PIN field and Confirm Security Key PIN field

  9. You will be prompted to touch your security key. Tap the circle on your YubiKey. You will prompted to touch the security key again.

     screenshot - Continue setup - Touch your security key
     
  10. You will be prompted to name your security key. You may name your key anything you like. The name is to differentiate this key from any other security keys that you might have registered. Select Next

     screenshot - Name your security key
     
  11. A window showing that the passkey was created will be displayed. Click Done.

    screenshot - Passkey created

Your YubiKey is now registered and ready to be used as your MFA method.
Note: If you have any issues after this step, navigate back to the Security Info page and select "Sign out everywhere" at the bottom. Then, continue with the instructions.

Step 4: Confirm YubiKey

Before enrolling in the required group, you must make sure that the YubiKey was successfully added. This is important to keep you from getting locked out. 
  1.  Go to the My Account page and sign in with your new YubiKey. 

  2. Under My Account, select the Security Info tab. This will show you a list of the sign-in methods that you have set up. Make sure your YubiKey was added by looking for: "Passkey (Device Bound)" with the name of your YubiKey beside it. If you do not see this option, the YubiKey was not added correctly. Return to Step 3 to try adding the YubiKey again.

    View the detailed guide below for a step-by-step demonstration on confirming your YubiKey:

Step 5: Enroll in "MFA with Passkey in Microsoft Authenticator" Group

After setting up and confirming the YubiKey, you will need to self-enroll in the Required Passkey group. 

ATTENTION: Do not complete this part if you are a student who uses Walton Virtual Labs, or you will be unable to log in. 
  1. After confirming that the YubiKey is in your list, select My Access in the left navigation pane.

  2. Under My Access in the left navigation, Select Access Packages.

    left navigation with Access packages indicated
     
  3. Select View All.

    Access packages page with View all indicated.

     
  4. Choose Request in the "MFA with Passkey in Microsoft Authenticator" row.

    Request link is indicated
     
  5. Select Continue when the window opens.

    MFA with Passkey in Microsoft Authenticator - Requesting for Myself
     
  6. Before enrolling in this group, answer the questions in the Additional Questions window:
    1. Select Yes or No to answer, "Have you registered a Microsoft passkey in Microsoft Authenticator or registered a YubiKey?"
    2. Select Yes or No to answer, "For Windows users, have you set up Windows Hello for Business?"
    3. You can leave the Business Justification field blank.
    4. Click the Submit Request button. 

      Additional questions window

A green message in the upper-left corner confirms your request was submitted. This will not take long to process.

Your request to add MFA with Passkey in Microsoft Authenticator is being processed.

You will receive an email to your UARK email account from Microsoft Security with the subject line, "You now have access to MFA with Passkey in Microsoft Authenticator" to let you know that you have successfully enrolled in the required security group. All steps are complete, and you are ready to use your YubiKey to access university resources. 

Using the YubiKey

Note: If you have set up a passkey, you might be prompted to authenticate with the passkey PIN. 

Note: You might be prompted to authenticate with your Windows Hello PIN. 

When multifactor authentication is required for a login, the YubiKey must be plugged into the computer or other device.

  1. Select Sign-in options.

    screenshot - Sign in window with Sign-in options button indicated
     
  2. Select Face, fingerprint, PIN, or security key.

    screenshot - sign-in options with Face, fingerprint, PIN or security key selected
     
  3. You will be prompted to Choose a passkey. Select Security Key.

    screenshot of Choose a passkey prompt with Security key indicated
     
  4. You will be prompted enter your security key PIN. Enter the PIN that you created during YubiKey registration in the Security Key PIN field, and click OK.

    screenshot - Sign in with a passkey prompt - Enter your security key PIN
     
  5. When prompted to Touch your security key, tap the YubiKey that is plugged into your device.

    screenshot - Sign in with a passkey - Touch your security key

After touching the YubiKey, you will be authenticated and logged into the system.

 

Troubleshooting NFC with YubiKeys and Security Keys

 

0% helpful - 1 review
Print Article

Related Articles (11)

This article is for faculty, staff, and student employees wanting to know more about passkey and why it is being implemented at the university as a multi-factor authentication method.
This article is for faculty, staff, student employees, and students who need to know what a YubiKey is, when one is required, and where to get one if needed.
The purpose of this policy is to provide guidelines for MFA connections to the University of Arkansas network and information systems on and off campus.
This article is for faculty, staff, student employees, and students that have frequently asked questions about using passkey.
The university creates a UARK account for each new student and each new employee. To set up your account, you must set a password and set up MFA.
Set up a new secondary/non-primary UARK account
Multi-factor authentication (MFA) is required for all student, faculty, and staff UARK accounts. After activating your UARK account, register for MFA.
Your UARK account allows you to securely access university services, including email, campus Wi-Fi, Blackboard, Workday, and more.
The easiest and most secure method for multi-factor authentication (MFA) is the Microsoft Authenticator app.
This FAQ answers common questions that faculty, staff, student employees, and students may run into when registering and using a YubiKey to access university systems.

Related Services / Offerings (1)