---
title: Setting Up Yubikeys with TruU
description: Setting up Yubikeys with TruU is fast and easy. See our step by step instruction page on how to enable Yubikey for your TruU installation today.
image: https://blog.truu.ai/hubfs/Blog%20Images/Blog_Yubikeys1_QR.png
---

[![TruU](https://blog.truu.ai/hubfs/raw_assets/public/Truu_September2021/images/logo.svg "TruU")](https://truu.ai/)

- [Why TruU](https://truu.ai/why-truu/)
- [Platform](https://truu.ai/platform/)
- [Partners](https://truu.ai/partners/)
- [Company](https://truu.ai/company/)
- [News](https://blog.truu.ai/)

[![Request a demo](https://hubspot-no-cache-na2-prod.s3.amazonaws.com/cta/default/7028263/97efe1a2-192d-41d0-a2f3-099d57d88341.png)](https://hubspot-cta-redirect-na2-prod.s3.amazonaws.com/cta/redirect/7028263/97efe1a2-192d-41d0-a2f3-099d57d88341)

![](https://blog.truu.ai/hubfs/Blog%20Images/Blog_Yubikeys1_QR.png)

# Setting Up Yubikeys with TruU

Posted by [The TruU Team](https://blog.truu.ai/author/truu) on August 10, 2020

![The TruU Team](https://blog.truu.ai/hubfs/Theme_Feb2020/Images/icon.png)

- [Tweet](https://twitter.com/share)

In speaking with customers and prospective customers, we understand that not all employees carry a smartphone, or may not wish to use their personal phone for access. To address this class of users, and to provide alternative login methods for users with smartphones, we are very excited to announce that we have added support for using FIDO hardware keys for passwordless access through TruU.

### Enterprise IAM Administrators Enable Yubikeys First

Admins can now enable their users to enroll FIDO2-compatible hardware keys as a way to identify themselves. Currently, FIDO hardware key support is limited to application access but is available for all of our SSO integrations. To see for yourself how this works, you will need to do the following:

1. Go to **‘Settings’** > **‘Security’** and check the box to **‘Include Option to Enroll a FIDO Token’** this will allow users to enroll a FIDO key through the enrollment interface.

![Blog_Yubikeys1_QR](https://blog.truu.ai/hs-fs/hubfs/Blog%20Images/Blog_Yubikeys1_QR.png?width=600&name=Blog_Yubikeys1_QR.png)

 

2. Go to **‘Policies’** > **‘Authentication’** and set the **‘Allow 3rd Party FIDO device in place of biometrics or PIN’** policy to **‘True’**.

![Blog_Yubikeys2_Authentification](https://blog.truu.ai/hs-fs/hubfs/Blog%20Images/Blog_Yubikeys2_Authentification.png?width=600&name=Blog_Yubikeys2_Authentification.png)

All apps federated with a single IdP will authenticate to the same origin (the IdP itself). We have made it very simple for this setup by automatically adding the origin for all existing SSO integrations. Management of those origins is available through the new **‘Settings’** > **‘FIDO’** > **‘Relying Party Origins’** menu, and individual origins can be modified by clicking on a specific SSO adapter from the **‘Integrations’** menu.

![Blog_Yubikeys3_Settings](https://blog.truu.ai/hs-fs/hubfs/Blog%20Images/Blog_Yubikeys3_Settings.png?width=600&name=Blog_Yubikeys3_Settings.png)

If your company has standardized on Yubikeys and wants to limit the enrollment of FIDO2-compatible hardware to devices from Yubico, you can do this by whitelisting the devices you wish to allow. This can be enabled by going to the **‘Settings’** > **‘FIDO’** > **‘Authorized Device Types’** menu, and choosing the option to whitelist FIDO device types.

#### End User Workflow for Enabling Yubikeys

With this in place, TruU end users can now authenticate using a FIDO2-compatible hardware key in lieu of a mobile device. When logging into an application that is enabled for TruU login, the user can now click a button to log in with a FIDO token which will start the FIDO login flow.

![Blog_Yubikeys4_Register_Mobile_App](https://blog.truu.ai/hs-fs/hubfs/Blog%20Images/Blog_Yubikeys4_Register_Mobile_App.png?width=6&name=Blog_Yubikeys4_Register_Mobile_App.png)![Blog_Yubikeys4_Register_Mobile_App](https://blog.truu.ai/hs-fs/hubfs/Blog%20Images/Blog_Yubikeys4_Register_Mobile_App.png?width=467&name=Blog_Yubikeys4_Register_Mobile_App.png)

![Blog_Yubikeys5_Mobile_App_login](https://blog.truu.ai/hs-fs/hubfs/Blog%20Images/Blog_Yubikeys5_Mobile_App_login.png?width=600&name=Blog_Yubikeys5_Mobile_App_login.png)

 

 Topics: [Blog](https://blog.truu.ai/tag/blog)

### Insights & Updates

Keep up with the latest in identity technology

We’re committed to your privacy. TruU uses the information you provide to us to contact you about our relavant content, products and services. You may unsubscribe from these communications at any time. For more information, checkout our [Privacy Policy](https://truu.ai/privacy/).

- [Why TruU](https://truu.ai/why-truu/)
- [Platform](https://truu.ai/platform/)
- [Partners](https://truu.ai/partners/)
- [Company](https://truu.ai/company/)
- [News](https://blog.truu.ai/)
- [Request a demo](https://truu.ai/request-a-demo/)

- <https://twitter.com/Truu_Security>
- <https://www.linkedin.com/company/truu-security>

Copyright © 2026 TruU, Inc. All rights reserved.

- [Privacy Statement](https://truu.ai/privacy/)
- [Terms Of Service](https://truu.ai/terms-of-service/)
- [GDPR/CCPA Requests](https://truu.ai/gdpr-ccpa-requests/)
- [Contact Us](https://truu.ai/contact/)