• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar

All Things Secured

Online Security Made Simple

FREE ONLINE SECURITY CHECKLIST! DOWNLOAD NOW

  • Security Basics
    • Start Here (Security Guide)
    • What is a Digital Footprint?
    • What is a VPN?
    • What is 2-Factor Authentication?
    • What is SmartDNS?
    • Bad Security Habits
    • Http vs Https?
  • VPN Security
    • Best VPNs 2024
    • Best Free VPNs 2024
    • VPN Reviews
      • ExpressVPN Review
      • Surfshark Review
      • NordVPN Review
      • ProtonVPN Review
      • VyprVPN Review
      • Mozilla VPN Review
      • IPVanish Review
      • Avast VPN Review
      • Ivacy VPN Review
      • PureVPN Review
    • Frequent Asked Questions
      • Are VPNs Illegal?
      • Tor vs VPN?
      • What is a VPN Kill Switch?
      • What is Split Tunneling?
      • Zero Log VPN?
      • Free VPN vs Paid VPN?
      • Lightway vs WireGuard vs OpenVPN
      • Increase Internet Speed on VPN?
      • How to Watch Netflix in China?
    • 10 Important VPN Features
    • 5 Best VPNs for Routers
    • Common VPN Myths
    • Common VPN Scams
    • VPN Connection Protocols Guide
  • Password Security
    • Password Manager Setup Guide
    • Best Password Managers 2024
      • 1Password Review
      • Dashlane Review
      • NordPass Review
      • Best iOS Password Manager
    • Frequently Asked Questions
      • How Do Password Managers Work?
      • Are Password Managers Safe?
      • Are Chrome Passwords Secure?
    • Double Blind Password Strategy
    • Using Google Authenticator
  • Email Security
    • Secure Email Providers in 2024
    • ProtonMail Review
    • Email Phishing Scams
  • Resources
    • Help! I’ve Been Hacked!
    • Password Strength Checker
    • Security Checklist PDF
    • Digital Death Checklist
  • About
    • Contact
    • Advertise

How to Setup a 2FA Security Key (Yubikey Tutorial)

September 27, 2024 By Josh 2 Comments

As online threats continue to grow, protecting your accounts has never been more crucial. Traditional username and password combinations are often not enough to safeguard your online identity, and that’s where two-factor authentication (2FA) comes in. One of the most robust forms of 2FA involves using a hardware security key, like a Yubikey.

Yubikey 2FA setup tutorial

In this guide, we’ll take you through the step-by-step process of setting up a Yubikey for 2FA, explain the difference between 2FA and passkeys, and help you decide which Yubikey is best for your needs.

2FA Key Setup Tutorial (Yubikey)

Setting up your Yubikey for 2FA is easier than you might think. Follow this simple tutorial, and you’ll have an added layer of protection for your online accounts in no time.

Step 1: Check if the Account is 2FA Key Compatible

While 2-factor authentication has been widely adopted, there are different ways to implement this security standard. Some online accounts only allow for SMS text or authenticator apps, which are less secure than a security key.

So how do you check if an account offers 2FA key compatibility?

  • Visit the 2FA Directory
  • Search for the online account or browse the categories
  • Search for 2FA “Hardware” support
2FA directory with hardware key support

If you don’t see the option, search the platform’s support or help pages for information on whether they support hardware security keys like Yubikey.

Step 2: Find Security & 2FA Settings

Once you’ve confirmed that the service is compatible with Yubikey, the next step is to locate the account’s security settings where 2FA can be activated. This will be different for each online login, but generally you’ll find these options under the “Security” or “Account Settings” section of the platform.

Protect yourself from identity theft
Go ahead. Forget your passwords. 1Password remembers them for you.

Let’s take Facebook as an example. To add a 2FA key, you will need to:

  1. Log in to your Facebook account;
  2. Navigate to the Security Settings (for Facebook, this happens in your Meta account);
  3. Find “Password and Security”
  4. Click on “Two-factor authentication”
  5. Turn this on and then click on “Security Keys” as you see below;
Facebook 2FA settings

Many platforms will require that you have a backup 2FA method created as well.

Step 3: Set Up a Primary & Backup Key (or Backup Codes)

When setting up your Yubikey, it’s always a good idea to have both a primary and a backup method in place (in other words, it’s worth the money to purchase two Yubikeys). This way, if your primary Yubikey is lost or damaged, you won’t be locked out of your account.

Here’s how to set up your Yubikey as your primary 2FA method. First, when prompted by the platform’s 2FA setup process, select the option for adding a security key.

Use security key with Facebook prompt

Sometimes you will be required to setup a PIN for your Yubikey. This is a security feature that will make sure that even if somebody steals your key, it’s still locked from being used without your permission.

Next, insert your Yubikey into the USB port of your computer or tap it to your mobile device if using NFC. Follow the on-screen instructions, which will usually involve pressing the button on the Yubikey to register it.

Plug in your Yubikey and tap it

Next, consider one of the following backup methods:

  • Add a second Yubikey: Many services allow you to register a backup key. You can store this second key in a safe place, so you’re covered if something happens to the primary one.
  • Generate backup codes: Some platforms provide one-time-use backup codes that you can store securely. These can be used to log in if your Yubikey isn’t available.

Remember: your account is only as strong as your strongest form of 2FA, so if you secure your account with a Yubikey but then allow for SMS text backup, you’ve essentially downgraded the security of your account (since SMS text is the weakest form of 2FA thanks to SIM swap attacks and other vulnerabilities).

Step 4: Using a 2FA Key for Login

Once your Yubikey is set up, logging in is straightforward:

  1. Go to the login page of the service.
  2. Enter your username and password as usual.
  3. When prompted for 2FA, insert your Yubikey into the device (or tap it, if using NFC).
  4. Press the button on the Yubikey to authenticate and complete the login process.

This process replaces the need for entering a code from an authenticator app or text message, providing a faster and more secure way to authenticate.

Difference Between 2FA & Passkeys (Both on Yubikey)

Yubikey offers two key security options: traditional 2FA and passkeys. While both provide secure authentication, they work in slightly different ways:

  • 2FA (Two-Factor Authentication): This involves adding an extra layer of security on top of your password. With Yubikey, after entering your password, you authenticate by physically tapping the key, ensuring that only someone with the key can log in.
  • Passkeys: Passkeys are designed to eliminate the need for passwords altogether (learn more: What is a passkey?). Instead of entering a password, you use your Yubikey to generate a cryptographic authentication process. This method is faster and less prone to phishing attacks since there’s no password to steal.

In essence, passkeys are the future of authentication, offering a simpler and more secure method than traditional password-based 2FA. Watch this video for an in-depth explanation of how passkeys work:

Be sure to subscribe to the All Things Secured YouTube channel!

Which Yubikey is Best?

Yubikey offers several models, each tailored to different devices and security needs. Here’s a quick overview of the most popular options:

  • Yubikey 5 Series: This is the most versatile model, supporting both USB-A and NFC, making it compatible with most computers and mobile devices. It’s an excellent choice if you want flexibility across platforms.
  • Yubikey Bio: This model adds biometric authentication (fingerprint) to the Yubikey experience, offering another layer of security. It’s ideal for those who want maximum protection.
  • Yubikey Security Key: A budget-friendly option, this model provides the basic functionality needed for 2FA but lacks some of the advanced features of the Yubikey 5 series.

For most individuals, the Security Key series will be enough for most of their security needs. The 5 series is geared more toward those advanced and enterprise users.

Secure your internet traffic with ExpressVPN
Get a Private Phone number for life with Hushed!

FAQ Troubleshooting

Here are some common questions and troubleshooting tips to help with your Yubikey setup:

What should I do if my Yubikey is lost?

Hopefully you’ve already set up a backup Yubikey or saved backup codes to access your account. After logging in, you can disable the lost key and set up a new one. If you have no backups, contact the service provider to see if you can recover access.

My Yubikey isn’t being recognized when I plug it in—what can I do?

Make sure the key is properly inserted and the USB port is functional. If the problem persists, try a different port or computer. For NFC issues, ensure your phone’s NFC is enabled and that you’re tapping the Yubikey correctly.

Can I use one Yubikey for multiple accounts?

Yes, you can register the same Yubikey with multiple services, making it a convenient tool for securing multiple accounts.

How do I keep my Yubikey safe?

Store your Yubikey in a secure place when not in use. Consider using a keychain attachment or case for portability. If using a backup Yubikey, store it separately to reduce the risk of losing both keys simultaneously.


By following these steps and tips, you can easily set up a Yubikey for 2FA, boosting the security of your online accounts. Whether you’re protecting personal data or business credentials, Yubikey offers an efficient and secure solution for modern digital threats.

Further Reading & Resources

  • 2FA Security Key tutorial
    2FA Security Key Setup Tutorial | How to Use Yubikey!
  • How to manually set up 2fa authenticator without a QR code
    How to MANUALLY Setup a 2FA Security (in 3 minutes!)

Download the Security Checklist!

A Free Resource from All Things Secured

    Reader Interactions

    Comments

    1. Avatar for Joshsteve parsons says

      December 12, 2024 at 5:40 pm

      Hi Josh,
      love your passion for ‘all things’ security. thanks.
      i have a question about the series 5 yubikeys which, unless i’ve missed it, i’ve not seen explained (in simple terms) for tech-dinosaurs like me!
      I notice that within the 5 series, there are differences with the USB connection … one has USB-C, another USB-A and I’ve also seen one with a lightning connector. i want to purchase from the yubikey 5 range yet i’m not sure which type of connector to get? my iphone is an 11, so still has lightning. my work laptop has usb-C and usb-A, whereas my personal laptop only has usb-A.

      a related question: should my backup yubikey have the same connection type or a different type? in all examples i’ve seen online, it appears the backup key has a different connection type. Perhaps this increases security, or just provides more options for some, i’m not sure.

      i appreciate any clarification you can give. and if you can send me a link, or direct me to a page on your site, i’m happy to purchase via you so you benefit in some way.

      many thanks

      steve (from Australia)

      Reply
      • Avatar for JoshJosh says

        December 15, 2024 at 8:49 pm

        Hey Steve, great questions. I would recommend just getting a key that fits the most number of devices that you have. For most people nowadays, that’s a USB-C but you’ll need to have a C-to-A adapter.

        As for the backup, it doesn’t matter as much as you think. There’s no added security having a different connection type. It’s easiest to just buy two of the same usually.

        Reply

    Leave a Reply Cancel reply

    Your email address will not be published. Required fields are marked *

    Primary Sidebar

    Download the free online security checklist!
    Check your password with this password checker by All Things Secured

    Best Personal Privacy Tools

    Use DeleteMe to Remove Your data onlineDeleteMe (remove personal data online)
    Use Traveling Mailbox to keep your address privateTraveling Mailbox (private virtual address)
    Hushed private second phone numberHushed (private 2nd phone line)

    Recommended Password Managers

    1Password Logo Mark1Password (Best Overall)
    Dashlane Logo MarkDashlane (Best for Businesses)
    Bitwarden Logo MarkBitwarden (Best Free Option)

    Best Secure Email Providers

    ProtonMail Logo MarkProtonMail (Best Gmail Alternative)
    StartMail Logo MarkStartmail (from StartPage)
    Mailfence Encrypted EmailMailfence

    Recommended VPNs

    ProtonVPN Logo MarkProtonVPN (Best Overall)
    NordVPN Logo MarkNordVPN (best for streaming)
    iVPN Logo MarkiVPN

    Best Identity Theft Protection

    Identity Guard Logo MarkIdentity Guard (Personally Recommended)

    Copyright © 2025 · Affiliate Disclaimer 
· Privacy Policy
 · Advertise
 · Contact