Body
Salesforce Admin Login: -a Account and YubiKey Setup
Salesforce requires phishing-resistant MFA for admin logins. Admin accounts must use a compliant authentication method, such as a YubiKey, to access Salesforce.
Admin accounts must also be -a accounts (e.g., jcowboy-a).
Follow the steps below to request a -a account and set up a YubiKey.
Use the ASO ERX request form to request your -a credentials and be added to the WyoLogin_Duo_Phishing_Resistant_Required Active Directory group.
Be sure to mention that you need a -a account and that you need to be added to the above AD group.
If you are reusing a YubiKey previously assigned to another employee, follow the How to Factory Reset a YubiKey knowledge base article.
Step 1: Request Your Initial Password
After your admin (-a) account has been created, contact the Help Desk to request your initial admin account password.
Step 2: Navigate to WyoWeb
Open WyoWeb in a browser or private browser window where you are not authenticated with your non-admin account.
Click Email.

Step 3: Sign In
Sign in using your -a account.

Use your regular username with -a appended to the end (ie. jcowboy-a) and the initial password received from the Help Desk.
Step 4: Set Up Duo Security
During your first login with your -a account, Duo will prompt you to set up security.
Follow the prompts to register your YubiKey.

Click Get started

You will be prompted similarly to this, and you will click Security key, then click Continue.

Wait for your operating system to prompt you to insert/use your YubiKey, then touch your YubiKey to authenticate.

Success! Now you can log in with your YubiKey.
Test logging into Salesforce with your YubiKey.
If you experience issues, visit our Salesforce Admin Login FAQ knowledge article or contact the Help Desk.