This ADMX administrative template allows administrators to easily deploy configuration of the YubiKey Smart Card Minidriver through Active Directory Group Policy or Microsoft Intune. It can also be used on standalone computers to unlock some features of the YubiKey Minidriver that are disabled by default, like controlling the touch policy or blocking the generation of unsafe keys (ROCA).
These are the YubiKey Minidriver settings that can currently be configured, with their default values highlighted:
The settings are on par with the 4.6.3.252 version of the Minidriver, released on May 21, 2024. Note that some settings are only applicable to devices that support slot metadata (YubiKey 5.2.7+).
Just copy the ADMX and ADML files into the local or central ADMX store.
Thanks to the awesome open-source community, the template has been translated into the following languages:
If you want to contribute with a new localization, you can create a language-specific copy of the en-US ADML file.
The ADMX template is based on the following official document: