<div dir="ltr"><div>Ken,<br>I was hoping to address your "two YubiKeys per staff member" issue by leveraging the Temporary Access Pass (TAP) authentication method. This allows a user admin to issue a temporary TAP that a user can use to (1) log into their account and (2) change their authentication methods. This way, the user retains a backdoor into their account if they lose their smartphone/YubiKey, but the library doesn't need to buy two for every staff member. You can buy just one for each and a small handful of unassigned spares that can be used only as needed. The theory seems reasonable; yet to be determined in practice.</div><div><br></div><div>Chad</div><div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div>______________________________<br><b>Chad Neeper</b><br><font size="1">Senior Systems Engineer</font><br><br><b>Level 9 Networks</b><br><font size="1">740-548-8070 (voice)<br>866-214-6607 (fax)</font><br><br><font size="1"><i>Full IT/Computer consulting services -- Specialized in public libraries</i></font><br></div></div></div></div></div></div><br></div><br><div class="gmail_quote gmail_quote_container"><div dir="ltr" class="gmail_attr">On Fri, Aug 28, 2026 at 11:07 AM Kenneth Butler via OPLINTECH <<a href="mailto:oplintech@lists.oplin.org">oplintech@lists.oplin.org</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div class="msg-5704129445819127418">
<div dir="ltr">
<div style="margin-top:1em;margin-bottom:1em;font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
I have been testing FIDO2 security keys (YubiKeys) with our administrative accounts, and they have worked very well. Once the keys are enrolled and configured, authentication is straightforward: plug in the key, enter the PIN when/if prompted, and touch the
key.</div>
<div style="margin-top:1em;margin-bottom:1em;font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
I am planning to roll them out to all of our staff. Our current plan is to purchase two keys for each employee: a primary key for daily use and a backup key that remains locked in a secure location. The backup would only be used if the primary key is lost,
damaged, or otherwise unavailable.</div>
<div style="margin-top:1em;margin-bottom:1em;font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
The biggest downside is cost. The YubiKeys we are considering are $58 each. Less expensive models support FIDO2 authentication alone, but we are purchasing models that support both FIDO2/WebAuthn and OTP/TOTP. This means they're not limited to Microsoft 365
and can also be used to secure vendor accounts that support TOTP but not FIDO2.</div>
<div style="margin-top:1em;margin-bottom:1em;font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
The other challenge is initial enrollment. Registering the keys through Microsoft 365’s web interface is not especially intuitive, so I expect to provide individual, hands-on assistance to each staff member during the rollout. Once we have the process established,
however, enrolling keys should be fairly easy to incorporate into our normal onboarding process for new employees.</div>
<div style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<br>
</div>
<div id="m_2946113858596682987Signature">
<div style="font-family:Calibri,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<span style="background-color:rgb(255,255,255)">Ken Butler</span></div>
<div style="font-family:Calibri,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<a href="mailto:hcotech@holmeslib.org" target="_blank">hcotech@holmeslib.org</a></div>
<div style="font-family:Calibri,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
Head of Information Technology</div>
<div style="font-family:Calibri,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
Holmes County District Public Library</div>
<div style="font-family:Calibri,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
3102 Glen Drive</div>
<div style="font-family:Calibri,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
Millersburg, OH 44654</div>
<div style="font-family:Calibri,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<span style="background-color:rgb(255,255,255)">PH: 330-674-5972 ext 224</span></div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<br>
</div>
</div>
<div id="m_2946113858596682987appendonsend"></div>
<hr style="display:inline-block;width:98%">
<div id="m_2946113858596682987divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> OPLINTECH <<a href="mailto:oplintech-bounces@lists.oplin.org" target="_blank">oplintech-bounces@lists.oplin.org</a>> on behalf of Fred Miller Jr via OPLINTECH <<a href="mailto:oplintech@lists.oplin.org" target="_blank">oplintech@lists.oplin.org</a>><br>
<b>Sent:</b> Thursday, August 27, 2026 11:45 AM<br>
<b>To:</b> <a href="mailto:oplintech@lists.oplin.org" target="_blank">oplintech@lists.oplin.org</a> <<a href="mailto:oplintech@lists.oplin.org" target="_blank">oplintech@lists.oplin.org</a>><br>
<b>Subject:</b> [OPLINTECH] Microsoft Office 365 Authentication Changes</font>
<div> </div>
</div>
<div lang="EN-US">
<div>
<p><span style="font-size:14pt;font-family:Arial,sans-serif;color:black">If your library system is using Microsoft Office 365, I would like to hear what some of the libraries around the state are doing regarding changes coming down
from Microsoft Office 365 since they are doing away with SMS/Voice authentication in February 2027. I know there are a few alternative authentication methods out there to use, but would like to get some feedback from other libraries on what method they prefer
and the pros/cons to using that authentication method. </span></p>
<p><span style="font-size:14pt;font-family:Arial,sans-serif;color:black"> </span></p>
<p><span style="font-size:14pt;color:black">Thanks in advance,</span></p>
<p><span style="font-size:12pt;color:black"> </span></p>
<p><span style="font-size:12pt;color:black"><img width="288" height="83" id="m_2946113858596682987x_Picture_x0020_1" alt="Logo Resized" style="width: 3in; height: 0.8645in;" src="cid:ii_1a048ea7bf75b006a1"></span></p>
<p><b><span style="font-size:12pt;color:rgb(89,89,89)"></span></b><b><span style="font-size:12pt;font-family:Arial,sans-serif;color:rgb(38,38,38)">203 Perry Street Wapakoneta, OH 45895</span></b></p>
<p><b><span style="font-size:12pt;color:rgb(89,89,89)"> </span></b></p>
<p><b><span style="font-size:14pt;color:rgb(38,38,38)">Fred Miller Jr</span></b></p>
<p><span style="font-size:14pt;color:black">IT Service Manager</span></p>
<p><b><span style="font-size:14pt;color:rgb(102,154,102)">T</span></b><span style="font-size:14pt;color:black">:
</span><u><span style="font-size:14pt;color:rgb(26,86,137)">419-738-1215</span></u><span style="font-size:14pt;color:rgb(0,112,192)">
</span><span style="font-size:14pt;color:black">|</span><b><span style="font-size:14pt;color:rgb(102,154,102)"> E</span></b><span style="font-size:14pt;color:black">:
</span><u><span style="font-size:14pt;color:rgb(26,86,137)"><a href="mailto:fmiller@auglaizelibraries.org" target="_blank">fmiller@auglaizelibraries.org</a></span></u><u><span style="font-size:14pt;color:rgb(0,112,192)"></span></u></p>
<p><span style="color:black"> </span></p>
<p> </p>
</div>
</div>
</div>
_______________________________________________<br>
OPLINTECH mailing list<br>
<a href="mailto:OPLINTECH@lists.oplin.org" target="_blank">OPLINTECH@lists.oplin.org</a><br>
<a href="https://lists.oplin.org/mailman/listinfo/oplintech" rel="noreferrer" target="_blank">https://lists.oplin.org/mailman/listinfo/oplintech</a><br>
<br>
****** Read about the new cybersecurity policy requirements for libraries Learn more at<br>
<a href="https://www.oplin.ohio.gov/security" rel="noreferrer" target="_blank">https://www.oplin.ohio.gov/security</a> ******<br>
</div></blockquote></div>