<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00007IWWJRCA5Okta Classic EngineMulti-Factor AuthenticationAnswered2025-08-27T09:00:32.000Z2021-11-22T00:05:32.000Z2021-11-22T22:00:52.000Z

190ai (190ai) asked a question.

Multiple YubiKeys for same shared account: OTP vs FIDO2 (WebAuthn)

Hi,

 

I'd like to provision and be able to use multiple YubiKeys as an MFA factor for the same shared account (it's a service account) on Okta--can this be done in either OTP or FIDO2 mode? Or is it only available in OTP mode?

 

Thanks,

Nghia


  • Chee-SengL.74757 (Customer)

    Hi Nghia,

     

    If the account is in Universal Directory and has a suitable MFA policy with FIDO2/WebAuthn, then you can have multiple FIDO2/WebAuthn factors associated with a single account.

     

    During MFA enrollment, you will need to set a PIN for WebAuthn and use a supported browser. Note if you have the same type of Yubikey, then it's hard to differentiate which key is which should you need to reset MFA.

    An admin can enroll the keys for the account, or the MFA can be enrolled when the account is logged in.

     

    I am not sure if this is the case for native Yubikey Factor Type configuration.

     

    Expand Post
This question is closed.
Loading
Multiple YubiKeys for same shared account: OTP vs FIDO2 (WebAuthn)