Michael Mongeau 

Yubikey FIDO U2F supported?

Is the Yubikey FIDO U2F security key supported by Okta for use with legacy MFA?



Mihai Balasa (Okta, Inc.)
Hello Michael,

The Yubikey MFA option is dependent on the Adaptive MFA feature.

The configuration guide here: https://support.okta.com/help/Documentation/Knowledge_Article/Using-YubiKey-Authentication-in-Okta

Michael Mongeau
Are you certain it is dependent on Adaptive MFA?  We do not currently have Adaptive MFA but I can see the YubiKey option under Security / Authentication.

From what I have read Adaptive MFA is just an intelligent analytics engine that can dynamically assign risk and take action based on behavior. I am just looking to use the YubiKey as a second factor for MFA.

Michael Mongeau
You should do your research before posting incorrect information.  My account manager sent me this document showing Okta MFA Features by Product and the Yubikey is supported with Legacy MFA.

Michael Mongeau

I am answering my own question for the benefit of others who may read this.

The YubiKey FIDO U2F cannot generate one-time passwords so it is not suited for applications that require OTP as a second factor.   They are not recognized by the Yubico Personalization Tool used to generate the seed file to register the keys in Okta.    

The keys can only be used with browsers that support them (currently Chrome and Firefox with a plugin).  The target application or service must also support them.   A list of those services can be found here.


Okta currently has early release support for FIDO U2F keys, so they will be supported for browser-based applications in the future.