.. intro.rst ============ Introduction ============ YubiEnroll enables administrators in organizations of all sizes to easily enroll YubiKeys on behalf of end users supporting the move to a passwordless and phishing-resistant enterprise. YubiEnroll is a software application that provides organizations with the ability to create FIDO credentials on YubiKeys, and configure and register the YubiKey with their identity provider on behalf of a user account. Pre-used YubiKeys can also be reset through YubiEnroll. For more information, see :ref:`about-yubienroll`. YubiEnroll offers a command line interface (CLI) through which an IT administrator can perform desired YubiKey configurations, for example to set minimum PIN length or force PIN change. When the YubiKey is configured, the IT admin can then enroll the YubiKey for a future key holder through the organizations' identity provider (currently Okta, Microsoft Entra ID, and PingOne PingID and PingOne AIC). For more information, see :ref:`using-cli`. Supported Platforms ====================== Yubienroll is compatible with and tested on Windows 11. If end users log in with admin-enrolled YubiKeys to systems on different platforms, they might encounter FIDO2 capabilities that are not yet supported. The following describes which FIDO CTAP2.1 features are natively supported by a platform. .. table:: :class: longtable +-----------------------------+-------------------------------------------------------+ | YubiEnroll Feature | Platforms supporting the feature on a YubiKey | +=============================+=======================================================+ | Minimum PIN length | Windows 11, Chrome on MacOS, Linux. | +-----------------------------+-------------------------------------------------------+ | Force PIN change before use | Windows 11, Chrome on MacOS, Linux. | +-----------------------------+-------------------------------------------------------+ | Require always UV | Windows 10\*\, Windows 11, macOS, Android, iOS, Linux.| +-----------------------------+-------------------------------------------------------+ \*\ On Windows 10, security keys enabled with ``Require always UV`` works with Okta, Microsoft Entra ID, PingOne PingID, and PingOne AIC. However, other websites supporting WebAuthn that do not request user verification, might block the user from logging in. Supported Identity Providers ============================= YubEnroll must be registered with the identity provider. Then the identity provider is added to YubiEnroll. YubiEnroll works with the following identity providers: .. table:: :class: longtable +--------------------------------+----------------------------------------------------------------------+ | Identity Provider | References | +================================+======================================================================+ | Microsoft Entra ID \*\ || Register YubiEnroll with MS Entra ID, see :ref:`entra-config` | | || Add Microsoft Entra ID to YubiEnroll, see :ref:`idp-entra-add` | +--------------------------------+----------------------------------------------------------------------+ | Okta || Register YubiEnroll with Okta, see :ref:`okta-config` | | || Add Okta to YubiEnroll, see :ref:`idp-okta-add` | +--------------------------------+----------------------------------------------------------------------+ | PingOne PingID || Register YubiEnroll with PingOne PingID, see :ref:`pingone-config` | | || Add PingOne PingID with YubiEnroll, see :ref:`idp-pingone-add` | +--------------------------------+----------------------------------------------------------------------+ || PingOne Advanced || Register YubiEnroll with PingOne AIC, see :ref:`pingone-aic-config` | || Identity Cloud (AIC) || Add PingOne AIC with YubiEnroll, see :ref:`idp-pingone-aic-add` | +--------------------------------+----------------------------------------------------------------------+ \*\ YubiEnroll with Microsoft Entra ID is currently in *Early Access*. For more information, see `YubiEnroll `_. Hardware ========== Configuration of YubiKeys through the YubiEnroll CLI supports the entire current Yubico hardware product portfolio including all types of YubiKeys. Supported interfaces where applicable are USB-A, USB-C, and NFC. .. Note:: The configuration options ``Min PIN length``, ``Require always UV``, and ``Force PIN change before use`` require YubiKeys with firmware version 5.5 and higher.