<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00008AWb8kCADOkta Classic EngineMulti-Factor AuthenticationAnswered2022-10-10T13:03:54.000Z2022-10-05T13:46:40.000Z2022-10-10T13:03:54.000Z

JyothsnaS.01792 (Customer) asked a question.

Reassign blocked YubiKeys to new users

Hi,

we have some of the keys showing in report as blocked. we would like those to be reassigned to other users.

we can delete the yubikey and generate seed file for that key alone.

My question is, if we upload that seed file then already existing keys and all details will get replaced with this alone key seed file? do i lose all the existing keys with valid assigned users with this new seed file having only one key details?

saw below steps in community post:

  1. Remove/disassociate YubiKey from the user object in Okta. - Is this same as deleting from Yubi key MFA screen.

Below it shows as unassigned but in report its blocked.

/help/servlet/rtaImage?refid=0EM4z000003Rc9p

2)Delete YubiKey entirely from the Okta console. - 

3)Reupload the seed for that key, by serial *, from the encrypted seed file.- Here does it replace all existing seeds and assignments?

4)Distribute the key to a new user.

5)Have them enroll the key as usual.

 


  • Thank you for contacting Okta . My name is Bogdan, and I will gladly assist you .

     

    The short answer it will be to that if you delete the unassigned/blocked YubiKeys it will not affect the current working users as you only "target" the YubikeKeys that are not used at that time.

    If you try to create a new seed file without deleting the invalid/blocked/unassigned YubyKeys you will get the "Seeds are either duplicates or not applicable" error message.

     

    Base on:

     

    Click View Report to view a list containing the serial values of all your assigned and unassigned YubiKeys. Alternatively, you can find the same information from the Reports page, under the MFA Usage link.

    A report can be run at any time to view:

    • Active tokens (YubiKeys which are associated with users.)
    • Blocked tokens (YubiKeys which were once active, but are now either reset by the end user or the Okta admin.)
    • Unassigned tokens (An unassigned YubiKey has secret values uploaded and is ready to be self enrolled by an end user.)
    • Names of assigned end users.

     

    Remove a lost, stolen, or invalid YubiKey

    • A user can be unauthorized from a YubiKey hard token if the token is lost or stolen.
    • A token is non-transferable and may be replaced. If an end user reports a lost or stolen YubiKey, unassign the token based on its unique serial number by using the same method to remove an unassigned YubiKey.
    • For auditing purposes, a YubiKey can't be deleted once assigned to a user. Even if it has been revoked or reassigned, it will remain in the report when generated.
    • A YubiKey must be deleted and re-uploaded to be reassigned to a user.
    • A YubiKey that has not been assigned to a user may be deleted.
    • A YubiKey serial can't be removed if it is currently active for a user.

    From the YubiKey tab:

    1. Enter the serial number into the Revoke YubiKey Seed field.
    2. Click the Find YubiKey button.
    3. Delete YubiKey modal appears to verify that you wish to permanently delete the YubiKey.
    4. A confirmation page appears. Click the Done button.

     

    Best Practice: If a lost YubiKey is found, it's a best practice to simply discard the old token. An admin can also reprogram the YubiKey by following the steps within the Programming YubiKeys for Okta file, which can be found in Configuring YubiKey Tokens. This generates a new Configuration Secrets file for upload, and allows the token to be re-enrolled by any end user within the Okta framework.

     

    You have additional questions or concerns I advise you to open a ticket with us using:

     

    Expand Post
This question is closed.
Loading
Reassign blocked YubiKeys to new users