How to Reassign a YubiKey to Another User in Okta
Last Updated:
Overview
This article provides steps on how to reassign a YubiKey to another user.
Applies To
- Multi-Factor Authentication (MFA)
- YubiKey
- Okta Classic Engine
- Okta Identity Engine (OIE)
Solution
To re-assign the YubiKey to another user, please follow the steps below.
Classic Tenant
- First, an MFA reset of the YubiKey authenticator is needed for the user who previously had the YubiKey in question assigned.
- Locate the Multifactor menu in the Okta Admin Console.
- Under Factor Type > select YubiKey.
- Under Revoke YubiKey Seed, enter the YubiKey Serial number that needs to be re-assigned to another user and click on the Find YubiKey button. The following Prompt should be received:
- Click on Delete. This will revoke the key in Okta's database. However, the status will appear UNASSIGNED until the end user enrolls their YubiKey.
- If one can locate the serial number in the Report or it shows as Revoke, it means the YubiKey has already been revoked in the database, and a CSV for this YubiKey that contains the serial number, public ID, private ID, and AES key needs to be manually created.
- Upload the seed file again, and then it should be possible to re-assign the YubiKey to another user. Please review Enroll a YubiKey for the first time on a desktop browser.
Okta Identity Engine (OIE) Tenant
- First, an MFA reset is needed for the user who previously had the YubiKey in question assigned.
- Locate the Authenticators menu in the Okta Admin Console.
- Under Setup > Select Actions under YubiKey OTP.
- Then Choose Revoke YubiKey OTP.
- Search the YubiKey Serial Number and hit Find.
- Then select Revoke.
- This will revoke the key in Okta's database. However, the status will appear UNASSIGNED (Check YubiKey Report) until the end user enrolls their YubiKey.
- If one can locate the serial number in the Report or it shows as Revoke, it means the YubiKey has already been revoked in the database, and a CSV for this YubiKey that contains the serial number, public ID, private ID, and AES key needs to be manually created.
- Upload the seed file again, and then it should be possible to re-assign the YubiKey to another user. Please review: Enroll a YubiKey on a desktop browser.
Related References
- Okta Classic Engine - YubiKey (MFA)
- Okta Identity Engine - Configure the YubiKey OTP authenticator
- How to test the YubiKey - Verify your YubiKey
