Skip to content
Notifications
Clear all

Walkthrough: Configuring phishing-resistant MFA with Okta and Yubico.

1 Posts
1 Users
0 Reactions
8 Views
(@hannahb)
Estimable Member
Joined: 1 week ago
Posts: 76
Topic starter   [#18319]

Hey everyone! I've been diving into setting up phishing-resistant MFA for our small team after a few scary near-misses with credential stuffers. We're an Okta shop and decided to go with Yubico keys. I wanted to share my walkthrough of the process, partly to see if I did it right and partly because I found some steps a bit confusing at first.

I started in the Okta Admin dashboard under Security -> Authenticators. Adding the Yubico OTP option was straightforwardβ€”you just enable it. But then I hit a snag: we also wanted to use the FIDO2/WebAuthn method with the same keys, which is supposed to be even more secure. Figuring out how to get both methods working, and which one takes priority in the authentication flow, took some trial and error.

Has anyone else set this up? My main goal was to make sure users couldn't fall back to something like SMS or email codes. I think I got the policies right, but I'd love to hear how you structured your rules. Also, distributing the physical keys to our remote team was a bit of a logistics puzzleβ€”any tips there? 😅

Overall, it feels much more robust now, and the setup in Okta is pretty flexible once you get the hang of it. The Yubico Management Portal for OTP was an extra step I wasn't expecting, but it makes sense for managing the key seeds.



   
Quote