Security Key (YubiKey) Enrollment
YubiKey (requires a hardware key)
An Emory-approved YubiKey is a good option if you prefer not to use a personal phone, or if you travel internationally often. The cost of the YubiKey is covered by you or your department; see the Emory YubiKey Guidance for approved models and procurement.
Adding Security Key (YubiKey)
On your computer
- Sign in to a Duo-protected application (or the Duo Self-Service Portal) with your Emory Network ID and password.

- At Welcome to Duo Security, select Get started.

- Choose Security key

Click Continue

Insert your security key into a USB port on your computer and touch the button.

Click Continue

A screen will ask if you want to add another way to log in. Click Skip for now.

Click Login to Duo to start using your Security Key

The Security Key now appears as a registered device.
- Sign in to a Duo-protected application (or the Duo Self-Service Portal) with your Emory Network ID and password.
Important: You cannot use a phone call, text message, or Duo Mobile passcode to manage devices. If those are your only options, contact the University Service Desk (404-727-7777) or Emory Healthcare IS Customer Service (404-778-4357).
On your computer
- In your browser, open the Duo Self-Service Portal and click Manage Duo.

- At the verification prompt, click Other options (do not send a passcode).

- Select Manage devices.

- Complete the identity verification Duo presents (for example, enter the code in Duo Mobile).

- On the device management page, click Add a device.

- Choose Security key

Click Continue

Insert your security key into a USB port on your computer and touch the button.

Click Continue

A screen will ask if you want to add another way to log in. Click Skip for now.

Click Login to Duo to start using your Security Key

The Security Key now appears as a registered device.
- In your browser, open the Duo Self-Service Portal and click Manage Duo.
(For Duo Multi-Factor Authentication and Research Compliance)
Overview
Emory provides free recommended options for Duo Multi-Factor Authentication (MFA). If you choose to purchase a YubiKey instead, please follow these guidelines to ensure compliance. Requirements differ for non-research users and research users.
Please note that if you choose to purchase a YubiKey, the expense will need to be covered by your department. Be sure to coordinate with your departmental administration to follow the appropriate procedures for procurement.
1. Non-Research Users
If you are not involved in research activities:
- Required Model: YubiKey Series 5
- Allowed Interfaces: USB-A, USB-C, NFC (any combination)
- Activation: Must include touch or bio-touch.
- Devices without touch activation are not allowed.
- FIPS-Certified Keys: Allowed but not required (not recommended).
- Biometric Keys: Not required and not recommended (adds unnecessary complexity).
- The following YubiKeys are recommended for Non-Research Users
Name | Part Number | Description | Recommended for |
Yubikey 5 USB A | B07HBD71HL | Yubico - YubiKey 5 NFC - Two-Factor authentication (2FA) Security Key, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts | Staff & Students |
Yubikey 5C USB C | B08DHL1YDL | Yubico - YubiKey 5C NFC - Two-Factor authentication (2FA) Security Key, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts | Staff & Students |
Yubikey 5Ci USB C and Lightning | B07WGJ1DNJ | Yubico - YubiKey 5Ci - Two-Factor authentication Security Key for Android/PC/iPhone, Dual connectors for Lighting/USB-C - FIDO Certified | Staff & Students |
2. Research Users
If your research requires NIST 800-171 compliance and you use YubiKeys for cryptographic operations like encryption or code-signing that involves the YubiKey, then a FIPS-compliant YubiKey is required.
- Required Model: YubiKey Series 5 FIPS
- Allowed Interfaces: USB-A, USB-C, NFC (any combination)
- Biometric Keys: Not required and not recommended.
- The following YubiKeys are recommended for Research Users
Name | Part Number | Description | Recommended for |
Yubikey 5C USB C (FIPS) | B0DC7315V5 | YubiKey 5C NFC FIPS | Researchers -Criteria defined in requirements doc |
Yubikey 5Ci USB C and Lightning (FIPS) | B0DC74JXDR | YUBICO YubiKey 5Ci FIPS | Researchers -Criteria defined in requirements doc |
Important Notes for Research Users
- FIPS-certified YubiKeys are validated under FIPS 140-2/3.
- Duo Federal is required for phishing-resistant MFA when FIPS compliance is mandated.
- Use of non-FIPS YubiKeys in research contexts may result in non-compliance with federal or agency requirements.
- MFA vs. Encryption: MFA itself does not need to be FIPS-validated unless used to protect Controlled Unclassified Information (CUI). The FIPS requirement applies specifically to cryptographic functions that secure the data.
