MichaelGrafnetter / yubikey-minidriver-admx

YubiKey Smart Card Minidriver Administrative Template (ADMX)
MIT License
14 stars 3 forks source link
active-directory admx piv pki windows yubikey

Administrative Template (ADMX) for YubiKey Smart Card Minidriver

Introduction

This ADMX administrative template allows administrators to easily deploy configuration of the YubiKey Smart Card Minidriver through Active Directory Group Policy or Microsoft Intune. It can also be used on standalone computers to unlock some features of the YubiKey Minidriver that are disabled by default, like controlling the touch policy or blocking the generation of unsafe keys (ROCA).

Screenshots

Group Policy Editor Screenshot 1

Group Policy Editor Screenshot 2

Available Settings

These are the YubiKey Minidriver settings that can currently be configured, with their default values highlighted:

The settings are on par with the 4.6.3.252 version of the Minidriver, released on May 21, 2024. Note that some settings are only applicable to devices that support slot metadata (YubiKey 5.2.7+).

Installation

Just copy the ADMX and ADML files into the local or central ADMX store.

Localization

Thanks to the awesome open-source community, the template has been translated into the following languages:

If you want to contribute with a new localization, you can create a language-specific copy of the en-US ADML file.

References

The ADMX template is based on the following official document: