Enrollment

YubiKey as a Service – Enrollment provides different options for organizations to pre-enroll a YubiKey, allowing their end users to instantly start using their YubiKey to authenticate with their identity providers, without first having to register the YubiKey.

Credential programming requests are initiated from the customers environment through integrations with the organization’s IT or HR systems and processes. A pre-enrollment request can either be fulfilled by Yubico, or by the customer using any of the available enrollment options described in the following.

Enrollment Options

The following enrollment options are available:

  • FIDO Pre-reg integration: With this option, the keys are factory-programmed by Yubico and shipped globally, from Yubico facilities directly to the end user. The service is available through API integrations with IdPs (identity providers).
  • Enroll app (Limited Early Access): This option lets an enrollment administrator access credential requests registered with the organization’s IdP, and program the credentials onto a YubiKey on-site, using a mobile device. The YubiKey is then provided to the end user.
  • YubiEnroll CLI tool: Using this option, a security administrator with access to the organization’s IdP, can program credentials onto a YubiKey on-site, on behalf of an end user. The YubiKey is then provided to the end user.

Each option is described in more detail in the following.

FIDO Pre-reg Integrations

FIDO Pre-reg is a fully managed enrollment service where Yubico programs the credentials onto the YubiKey, which is shipped directly to the recipient. A randomly generated PIN is sent separately to the recipient, who immediately can authenticate with their pre-enrolled YubiKey.

The FIDO Pre-reg service is available through the Yubico-provided FIDO Pre-reg API for integration with an organization’s IdP and IT environment. A request for shipment of an enrolled YubiKey can for example be triggered from corporate systems such as ServiceNow.

When the key has been shipped, the security administrator can monitor and manage any shipment issues in the Customer Portal. See Managing Enrolled Shipments.

Yubcio provides FIDO Pre-reg integrations for the following IdPs:

Enroll App

The Enroll app (Limited Early Access) option enables enrollment administrators to securely program credentials onto a YubiKey outside of Yubico premises, using a mobile device. The Enroll app extends the capabilities of the FIDO Pre-reg service to support decentralized enrollment, and does not require administrative privileges within the organization’s IdP.

A typical usage scenario for the Enroll app is when an organization has received a bulk shipment of YubiKeys to their on-site location. A new-hired employee needs a YubiKey, and a credential request for that end user is initiated through a corporate system, for example via the organization’s HR or IT administration.

Through the Yubico Enrollment service, the credentials are registered with the organization’s IdP. The credentials are then securely provided to the enrollment administrator, who uses the Enroll app and the NFC feature on a mobile device to program the credentials onto a YubiKey, which is then handed over to the end user.

YubiEnroll CLI Tool

Using YubiEnroll, a user, for example a security administrator, can program credentials onto a YubiKey on-site, and then hand over the enrolled key to the end user. This option requires that the user who does the programming has administrator privileges in the organization’s IdP.

YubiEnroll is available as a command line tool with support for IdPs Okta, Microsoft Entra ID, and PingOne PingID/AIC. For more information, see the YubiEnroll User Guide.

Managing Enrolled Shipments

The following provides an overview of how to work with shipments of FIDO Pre-reg pre-enrolled YubiKeys. These shipment requests are created through integrations with different IdPs, as described in FIDO Pre-reg Integrations.

Viewing Enrolled Shipments

Just as for other types of shipment requests, you can monitor the status of pre-enrolled shipments for your organization in the Shipments page of the Customer Portal. Pre-enrolled shipments are indicated as AUTO FIDO PRE-REG in the Shipment type column on the page.

To locate a specific shipment of pre-enrolled YubiKeys, do the following:

  • Use the Filters function to filter out pre-enrolled shipments. Click Filters, select “Auto FIDO Pre-reg” as Shipment type, and click Apply.
  • You can also use search in combination with filters to drill down further into the list of shipments. For more information, see Searching Shipments.
_images/prereg-filter3.png

Editing Enrolled Shipments

Just as for other types of shipments, you can update a pre-enrolled shipment from the Customer Portal until it is locked for processing and fulfillment. Shipments that can be edited are indicated with an Edit icon in the Shipment status column of the Shipments page.

You can update the recipient and address information, the delivery type, or you can delete the shipment request. Note that products included in a pre-enrolled shipment request cannot be modified. For more information, see Editing and Deleting Shipments.

Viewing Customization Information

A pre-enrolled YubiKey is considered a customization, and therefore Yubico provides a unique Customization ID which is also required for the FIDO Pre-reg integration. To view your organization’s Customization ID, see Customizations.