Security Key (YubiKey) Enrollment

 

YubiKey (requires a hardware key)

 

An Emory-approved YubiKey is a good option if you prefer not to use a personal phone, or if you travel internationally often. The cost of the YubiKey is covered by you or your department; see the Emory YubiKey Guidance for approved models and procurement.

Adding Security Key (YubiKey)

On a computer (Pc or Mac)

    1. Sign in to a Duo-protected application (or the Duo Self-Service Portal) with your Emory Network ID and password.

      1

    2. At Welcome to Duo Security, select Get started.
      2
    3. Choose Security key 

      3

    4. Click Continue
      5

    5. Insert your security key into a USB port on your computer and touch the button.
      22

    6. Click Continue
      33

    7. A screen will ask if you want to add another way to log in. Click Skip for now.
      55

    8. Click Login to Duo to start using your Security Key
      44

    9. The Security Key now appears as a registered device.

Important: You cannot use a phone call, text message, or Duo Mobile passcode to manage devices. If those are your only options, contact the University Service Desk (404-727-7777) or Emory Healthcare IS Customer Service (404-778-4357).

On a computer (Pc or Mac)

    1. In your browser, open the Duo Self-Service Portal and click Manage Duo.

       1

    2. At the verification prompt, click Other options (do not send a passcode).

       3

    3. Select Manage devices.

      2

    4. Complete the identity verification Duo presents (for example, enter the code in Duo Mobile).

      4

    5. On the device management page, click Add a device.

      5

    6. Choose Security key 

      3

    7. Click Continue
      5

    8. Insert your security key into a USB port on your computer and touch the button.
      22

    9. Click Continue
      33

    10. A screen will ask if you want to add another way to log in. Click Skip for now.
      55

    11. Click Login to Duo to start using your Security Key
      44

    12. The Security Key now appears as a registered device.


Emory YubiKey Acquisition Guidelines

 

Overview

 

Emory provides free recommended options for Duo Multi-Factor Authentication (MFA). If you do not want to use a personal device for their MFA or any of the other free options provided by Emory, the user at their or their department's expense will need to acquire and use a YubiKey hardware token for Duo MFA purposes. If you work for Emory and you desire to have a YubiKey provided to you, you will need to coordinate with your departmental administration and follow your respective departmental procedures for procurement.

Emory YubiKey requirements differ for non-research users and research users. So, please carefully review the requirements below to determine the right YubiKey to acquire.

 

1. Non-Research Users

 

If you are not involved in research activities:

  • Required Model: YubiKey Series 5
  • Allowed Interfaces: USB-A, USB-C, NFC (any combination)
  • Activation: Must include touch or bio-touch.
    • Devices without touch activation are not allowed.
  • FIPS-Certified Keys: Allowed but not required (not recommended).
  • Biometric Keys: Not required and not recommended (adds unnecessary complexity).
  • The following YubiKeys are recommended for Non-Research Users

Name

Part Number

Description

Recommended for

Yubikey 5 USB A

B07HBD71HL

Yubico - YubiKey 5 NFC - Two-Factor authentication (2FA) Security Key, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts

Staff & Students

Yubikey 5C USB C

B08DHL1YDL

Yubico - YubiKey 5C NFC - Two-Factor authentication (2FA) Security Key, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts

Staff & Students

Yubikey 5Ci USB C and Lightning

B07WGJ1DNJ

Yubico - YubiKey 5Ci - Two-Factor authentication Security Key for Android/PC/iPhone, Dual connectors for Lighting/USB-C - FIDO Certified

Staff & Students

 

2. Research Users

 

If your research requires NIST 800-171 compliance and you use YubiKeys for cryptographic operations like encryption or code-signing that involves the YubiKey, then a FIPS-compliant YubiKey is required.

  • Required Model: YubiKey Series 5 FIPS
  • Allowed Interfaces: USB-A, USB-C, NFC (any combination)
  • Biometric Keys: Not required and not recommended.
  • The following YubiKeys are recommended for Research Users

 

Name

Part Number

Description

Recommended for

Yubikey 5C USB C (FIPS)

B0DC7315V5

YubiKey 5C NFC FIPS

Researchers -Criteria defined in requirements doc

Yubikey 5Ci USB C and Lightning (FIPS)

B0DC74JXDR

YUBICO YubiKey 5Ci FIPS

Researchers -Criteria defined in requirements doc

 

Important Notes for Research Users

  • FIPS-certified YubiKeys are validated under FIPS 140-2/3.
  • Duo Federal is required for phishing-resistant MFA when FIPS compliance is mandated.
  • Use of non-FIPS YubiKeys in research contexts may result in non-compliance with federal or agency requirements.
  • MFA vs. Encryption: MFA itself does not need to be FIPS-validated unless used to protect Controlled Unclassified Information (CUI). The FIPS requirement applies specifically to cryptographic functions that secure the data.