This ADMX administrative template allows administrators to easily deploy configuration of the YubiKey Smart Card Minidriver through Active Directory Group Policy. It can also be used on standalone computers to unlock some features of the YubiKey Minidriver that are disabled by default, like controlling the touch policy or blocking the generation of unsafe keys (ROCA).
These are the YubiKey Minidriver settings that can currently be configured, with their default values highlighted:
- Configure touch policy for new keys
- Never
- Always
- Cached
- Enable ROCA mitigation
- Enabled
- Disabled
- Enable debug logging
- Enabled
- Disabled
Just copy the ADMX and ADML files into the local or central ADMX store.
The ADMX template is based on the following official document: