
JyothsnaS.01792 (Customer) asked a question.
Hi,
we have some of the keys showing in report as blocked. we would like those to be reassigned to other users.
we can delete the yubikey and generate seed file for that key alone.
My question is, if we upload that seed file then already existing keys and all details will get replaced with this alone key seed file? do i lose all the existing keys with valid assigned users with this new seed file having only one key details?
saw below steps in community post:
- Remove/disassociate YubiKey from the user object in Okta. - Is this same as deleting from Yubi key MFA screen.
Below it shows as unassigned but in report its blocked.
2)Delete YubiKey entirely from the Okta console. -
3)Reupload the seed for that key, by serial *, from the encrypted seed file.- Here does it replace all existing seeds and assignments?
4)Distribute the key to a new user.
5)Have them enroll the key as usual.

Thank you for contacting Okta . My name is Bogdan, and I will gladly assist you .
The short answer it will be to that if you delete the unassigned/blocked YubiKeys it will not affect the current working users as you only "target" the YubikeKeys that are not used at that time.
If you try to create a new seed file without deleting the invalid/blocked/unassigned YubyKeys you will get the "Seeds are either duplicates or not applicable" error message.
Base on:
Click View Report to view a list containing the serial values of all your assigned and unassigned YubiKeys. Alternatively, you can find the same information from the Reports page, under the MFA Usage link.
A report can be run at any time to view:
Remove a lost, stolen, or invalid YubiKey
From the YubiKey tab:
Best Practice: If a lost YubiKey is found, it's a best practice to simply discard the old token. An admin can also reprogram the YubiKey by following the steps within the Programming YubiKeys for Okta file, which can be found in Configuring YubiKey Tokens. This generates a new Configuration Secrets file for upload, and allows the token to be re-enrolled by any end user within the Okta framework.
You have additional questions or concerns I advise you to open a ticket with us using: