Security key Registration
Register the authenticator and assign it to a Windows account.
There are two ways to register a security key: from the configuration tool or from the logon screen.
Installation of YubiOn FIDO Logon client software must be completed.
A security key is required for registration.
For security keys that require PIN or biometric (fingerprint, etc.) registration, PIN registration can be done on the FIDO Logon software, but biometric settings must be done separately.
The operation method of the security key varies depending on the vendor of the device you are using. Please refer to the vendor’s manual or our published security key setup instructions.
End-user operations
Register the security key in your hand.
Once registered, the authenticator will be linked to the Windows account you are logging on to.
-
On your PC, select Start > YubiOn > FIDO Logon Configuration Tool to launch the YubiOn FIDO Logon Configuration Tool.
-
Select "Authentication Settings" from the left menu of the Configuration Tool.
-
Click on the "Register security key" button.
-
Connect the authenticator to your PC.
-
Operate the authenticator.
How to operate the authenticator
The operation of the authenticator depends on your device.
For fingerprint-type FIDO2 security key
Touch the device to read the fingerprint.
* If the fingerprint is not registered, the operation is the same as that of a PIN type security key.
For PIN-type FIDO2 security key
If a PIN has already been set, enter the PIN.
If the PIN has not been set, a screen for setting a PIN for the security key will appear.
For U2F security key
Touch the device to proceed with registration.
-
Registration is complete.
Prerequisite
To register from the logon screen, the following conditions must be met
- The version of the installed configuration tool must be 3.1.0.1 or later.
- No authenticator assigned to the account to log on to.
- "Logon to authenticator-less account" policy is set to "Logon with password only the first time and enforce authenticator registration" (administrator operation).
-
Displays the logon screen.
The first time, you will need to enter the password for your Windows account.
-
Click "OK".
-
If the security key is not inserted into the USB port, insert it.
-
Operate the authenticator.
How to operate the authenticator
The operation of the authenticator depends on your device.
For fingerprint-type FIDO2 security key
Touch the device to read the fingerprint.
* If the fingerprint is not registered, the operation is the same as that of a PIN type security key.
For PIN-type FIDO2 security key
If a PIN has already been set, enter the PIN.
If the PIN has not been set, a screen for setting a PIN for the security key will appear.
For U2F security key
Touch the device to proceed with registration.
-
The security key is registered.
This completes the setup.
For information on how to log on to Windows, please refer to the User’s Manual.
Administrator operations
Check the registration status of the PC.
- Access the login screen of the web administration site.
- Log in to the web administration site with your registered email address and password.
- Select Authentication Service > PC from the left menu.
- Verify that the end user’s PC is registered.