<div dir="ltr"><div>I've been digging into this myself. While I understand the need... What a pain for a bunch of smaller libraries! I have enough to do already, LOL!</div><div><br></div><div>Disclaimer1: I'm no expert in M365 matters. I'm a "Jack-of-all-trades," whereas some people have built entire careers around M$.</div><div>Disclaimer2:  I've only been using passkeys myself for the past ~5-6 months, but via a more unusual method. I store them in my KeePass password manager and have never actually used a YubiKey or other hardware security key, nor do I use Microsoft Authenticator or another app on my smartphone as a passkey storage device.</div><div><br></div><div>From my perspective, this may be a key phrase in Microsoft's announcement: "Move to <u><i><b>phishing-resistant</b></i></u> authentication before SMS and voice retire"</div><div>Also notable is the firm D-Day deadline of February 2027, when SMS/voice will go offline (caveat: unless you're fancy enough to run your own system) and any users configured for that authentication method may be locked out of their account.</div><div><br></div><div>MS is strongly preferring <u>phishing-resistant</u> authentication methods. It's probably safe to assume that over time, they'll increasingly discourage other non-phishing-resistant methods besides just the least secure SMS/voice. So, if we have to force the staff to deal with this, we might as well try to stick with methods that aren't next in line to be discouraged. This leaves us with: Passkey (FIDO2), Passkey in Microsoft Authenticator, Windows Hello, and Cert-based authentication. For my own libraries, Windows Hello isn't an option, nor is cert-based auth. That leaves us with Passkey. This means staff will need to use their own smartphone, leveraging Passkeys via Microsoft Authenticator (or some other Passkey app), or they'll need to be issued a library-owned hardware-based USB key. In some cases, an employee may have a library-owned smartphone or another device that could be used for Passkey, but that doesn't really apply to my own libraries.</div><div><br></div><div>So, taking this a step further:  "Oh crap, I lost my hardware key/smartphone. I can't log in! Help!"  (You <i>know</i> it's going to happen.) I'm enabling the Temporary Access Pass (TAP) authentication method too. This allows an admin to issue a one-time-use TAP (in my initial planned configuration) that a user can use to 1) log into their account, and 2) change their authentication methods. This allows them to register a new phone or hardware device. By combining passkey+TAP:</div><div>1) Staff use their personal smartphone</div><div>2) Staff who can't or refuse to use their personal smartphone can be issued a library-owned hardware security device (e.g., YubiKey).</div><div>3) The library can keep just a few extra hardware devices as replacements instead of issuing every user multiple devices (one for primary, another for backup)</div><div><br></div><div>If someone sees a fatal flaw in this strategy, I'm all ears!!</div><div><br></div><div><br></div><div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div>______________________________<br><b>Chad Neeper</b><br><font size="1">Senior Systems Engineer</font><br><br><b>Level 9 Networks</b><br><font size="1">740-548-8070 (voice)<br>866-214-6607 (fax)</font><br><br><font size="1"><i>Full IT/Computer consulting services -- Specialized in public libraries</i></font><br></div></div></div></div></div></div><br></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Thu, Aug 27, 2026 at 11:45 AM Fred Miller Jr via OPLINTECH <<a href="mailto:oplintech@lists.oplin.org" target="_blank">oplintech@lists.oplin.org</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div>





<div lang="EN-US">
<div>
<p class="MsoNormal"><span style="font-size:14pt;font-family:Arial,sans-serif;color:black">If your library system is using Microsoft Office 365, I would like to hear what some of the libraries around the state are doing regarding changes coming down from
 Microsoft Office 365 since they are doing away with SMS/Voice authentication in February 2027. I know there are a few alternative authentication methods out there to use, but would like to get some feedback from other libraries on what method they prefer and
 the pros/cons to using that authentication method. <u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:14pt;font-family:Arial,sans-serif;color:black"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:14pt;color:black">Thanks in advance,<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:12pt;color:black"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:12pt;color:black"><img width="288" height="83" style="width: 3in; height: 0.8645in;" id="m_3813174589016739750m_-8778774933866186075Picture_x0020_1" src="cid:ii_1a043ea0d095b006a1" alt="Logo Resized"><u></u><u></u></span></p>
<p class="MsoNormal"><b><span style="font-size:12pt;color:rgb(89,89,89)"></span></b><b><span style="font-size:12pt;font-family:Arial,sans-serif;color:rgb(38,38,38)">203 Perry Street Wapakoneta, OH 45895<u></u><u></u></span></b></p>
<p class="MsoNormal"><b><span style="font-size:12pt;color:rgb(89,89,89)"><u></u> <u></u></span></b></p>
<p class="MsoNormal"><b><span style="font-size:14pt;color:rgb(38,38,38)">Fred Miller Jr<u></u><u></u></span></b></p>
<p class="MsoNormal"><span style="font-size:14pt;color:black">IT Service Manager<u></u><u></u></span></p>
<p class="MsoNormal"><b><span style="font-size:14pt;color:rgb(102,154,102)">T</span></b><span style="font-size:14pt;color:black">:
</span><u><span style="font-size:14pt;color:rgb(26,86,137)">419-738-1215</span></u><span style="font-size:14pt;color:rgb(0,112,192)">
</span><span style="font-size:14pt;color:black">|</span><b><span style="font-size:14pt;color:rgb(102,154,102)"> E</span></b><span style="font-size:14pt;color:black">:
</span><u><span style="font-size:14pt;color:rgb(26,86,137)"><a href="mailto:fmiller@auglaizelibraries.org" target="_blank">fmiller@auglaizelibraries.org</a></span></u><u><span style="font-size:14pt;color:rgb(0,112,192)"><u></u><u></u></span></u></p>
<p class="MsoNormal"><span style="color:black"><u></u> <u></u></span></p>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
</div>

_______________________________________________<br>
OPLINTECH mailing list<br>
<a href="mailto:OPLINTECH@lists.oplin.org" target="_blank">OPLINTECH@lists.oplin.org</a><br>
<a href="https://lists.oplin.org/mailman/listinfo/oplintech" rel="noreferrer" target="_blank">https://lists.oplin.org/mailman/listinfo/oplintech</a><br>
<br>
****** Read about the new cybersecurity policy requirements for libraries Learn more at<br>
<a href="https://www.oplin.ohio.gov/security" rel="noreferrer" target="_blank">https://www.oplin.ohio.gov/security</a> ******<br>
</div></blockquote></div>