<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div class="elementToProof" style="margin-top: 1em; margin-bottom: 1em; font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
I think Chad is on the right track.</div>
<div class="elementToProof" style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Phishing-resistant authentication is the goal, and passkeys are our best option. Systems relying on rolling codes or number matching are not phishing-resistant. While passkeys are new for users, they are arguably easier to understand: a passkey is something
 you have rather than something you know, and attackers cannot easily steal a physical device. There's also AiTM safeguards, but that's a technical rabbit hole.</div>
<div class="elementToProof" style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Within Entra, we should require device-bound passkeys (such as Microsoft Authenticator and FIDO2 security keys) to prevent organizational credentials from syncing to personal cloud accounts (like Apple iCloud Keychain or Google Password Manager).</div>
<div class="elementToProof" style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
For users unable or unwilling to use a mobile phone, we can provide a security key. We can also deploy contactless NFC readers at shared service points to support tap-to-sign-in for MFA and Windows login.</div>
<div class="elementToProof" style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Yubico Security Key NFC: <a href="https://www.amazon.com/dp/B0BVNPWPCN">https://www.amazon.com/dp/B0BVNPWPCN</a></div>
<div class="elementToProof" style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Contactless Reader: <a href="https://www.amazon.com/dp/B079T2FKN1">https://www.amazon.com/dp/B079T2FKN1</a></div>
<div class="elementToProof" style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Windows Hello for Business will serve as a device-bound passkey for our dedicated 1:1 workstations. Users can have multiple independent passkeys to the same Entra account.</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div id="Signature" class="elementToProof">
<div class="elementToProof" style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<b>Karl Jendretzky</b> | Senior Manager of IT Engineering & Cybersecurity</div>
<div class="elementToProof" style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<b>Columbus Metropolitan Library</b> │ Main Library</div>
<div class="elementToProof" style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
96 S. Grant Ave. | Columbus, OH  43215</div>
<div class="elementToProof" style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
614.479.3039 office</div>
<div class="elementToProof" style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
kjendretzky@columbuslibrary.org | <a href="https://www.columbuslibrary.org/" id="OWA59ab76b2-d938-405b-eadc-49d305ad295b" class="OWAAutoLink" title="https://www.columbuslibrary.org/">
columbuslibrary.org</a></div>
</div>
<div id="appendonsend"></div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> OPLINTECH <oplintech-bounces@lists.oplin.org> on behalf of Chad Neeper via OPLINTECH <oplintech@lists.oplin.org><br>
<b>Sent:</b> Thursday, August 27, 2026 12:33 PM<br>
<b>To:</b> Fred Miller Jr <fmiller@auglaizelibraries.org><br>
<b>Cc:</b> oplintech@lists.oplin.org <oplintech@lists.oplin.org><br>
<b>Subject:</b> *External* Re: [OPLINTECH] Microsoft Office 365 Authentication Changes</font>
<div> </div>
</div>
<div>
<p class="x_MsoNormal"> </p>
<div style="border:solid RED 2.0pt; padding:2.0pt 2.0pt 2.0pt 2.0pt">
<p class="x_MsoNormal" style="line-height:12.0pt; background:yellow"><b><span style="font-size:10.0pt; font-family:"Arial",sans-serif; color:RED">EXTERNAL EMAIL WARNING!</span></b><span style="font-size:10.0pt; font-family:"Arial",sans-serif; color:red"> This
 email originated from outside of the organization. Use caution with links or attachments unless you trust the sender and know the content is safe. DO NOT PROVIDE YOUR CREDENTIALS!</span></p>
</div>
<p class="x_MsoNormal"> </p>
<div></div>
<div>
<div dir="ltr">
<div>I've been digging into this myself. While I understand the need... What a pain for a bunch of smaller libraries! I have enough to do already, LOL!</div>
<div><br>
</div>
<div>Disclaimer1: I'm no expert in M365 matters. I'm a "Jack-of-all-trades," whereas some people have built entire careers around M$.</div>
<div>Disclaimer2:  I've only been using passkeys myself for the past ~5-6 months, but via a more unusual method. I store them in my KeePass password manager and have never actually used a YubiKey or other hardware security key, nor do I use Microsoft Authenticator
 or another app on my smartphone as a passkey storage device.</div>
<div><br>
</div>
<div>From my perspective, this may be a key phrase in Microsoft's announcement: "Move to
<u><i><b>phishing-resistant</b></i></u> authentication before SMS and voice retire"</div>
<div>Also notable is the firm D-Day deadline of February 2027, when SMS/voice will go offline (caveat: unless you're fancy enough to run your own system) and any users configured for that authentication method may be locked out of their account.</div>
<div><br>
</div>
<div>MS is strongly preferring <u>phishing-resistant</u> authentication methods. It's probably safe to assume that over time, they'll increasingly discourage other non-phishing-resistant methods besides just the least secure SMS/voice. So, if we have to force
 the staff to deal with this, we might as well try to stick with methods that aren't next in line to be discouraged. This leaves us with: Passkey (FIDO2), Passkey in Microsoft Authenticator, Windows Hello, and Cert-based authentication. For my own libraries,
 Windows Hello isn't an option, nor is cert-based auth. That leaves us with Passkey. This means staff will need to use their own smartphone, leveraging Passkeys via Microsoft Authenticator (or some other Passkey app), or they'll need to be issued a library-owned
 hardware-based USB key. In some cases, an employee may have a library-owned smartphone or another device that could be used for Passkey, but that doesn't really apply to my own libraries.</div>
<div><br>
</div>
<div>So, taking this a step further:  "Oh crap, I lost my hardware key/smartphone. I can't log in! Help!"  (You
<i>know</i> it's going to happen.) I'm enabling the Temporary Access Pass (TAP) authentication method too. This allows an admin to issue a one-time-use TAP (in my initial planned configuration) that a user can use to 1) log into their account, and 2) change
 their authentication methods. This allows them to register a new phone or hardware device. By combining passkey+TAP:</div>
<div>1) Staff use their personal smartphone</div>
<div>2) Staff who can't or refuse to use their personal smartphone can be issued a library-owned hardware security device (e.g., YubiKey).</div>
<div>3) The library can keep just a few extra hardware devices as replacements instead of issuing every user multiple devices (one for primary, another for backup)</div>
<div><br>
</div>
<div>If someone sees a fatal flaw in this strategy, I'm all ears!!</div>
<div><br>
</div>
<div><br>
</div>
<div>
<div dir="ltr" class="x_gmail_signature" data-smartmail="gmail_signature">
<div dir="ltr">
<div>
<div dir="ltr">
<div>______________________________<br>
<b>Chad Neeper</b><br>
<font size="1">Senior Systems Engineer</font><br>
<br>
<b>Level 9 Networks</b><br>
<font size="1">740-548-8070 (voice)<br>
866-214-6607 (fax)</font><br>
<br>
<font size="1"><i>Full IT/Computer consulting services -- Specialized in public libraries</i></font><br>
</div>
</div>
</div>
</div>
</div>
</div>
<br>
</div>
<br>
<div class="x_gmail_quote">
<div dir="ltr" class="x_gmail_attr">On Thu, Aug 27, 2026 at 11:45 AM Fred Miller Jr via OPLINTECH <<a href="mailto:oplintech@lists.oplin.org" target="_blank">oplintech@lists.oplin.org</a>> wrote:<br>
</div>
<blockquote class="x_gmail_quote" style="margin:0px 0px 0px 0.8ex; border-left:1px solid rgb(204,204,204); padding-left:1ex">
<div>
<div lang="EN-US">
<div>
<p class="x_MsoNormal"><span style="font-size:14pt; font-family:Arial,sans-serif; color:black">If your library system is using Microsoft Office 365, I would like to hear what some of the libraries around the state are doing regarding changes coming down from
 Microsoft Office 365 since they are doing away with SMS/Voice authentication in February 2027. I know there are a few alternative authentication methods out there to use, but would like to get some feedback from other libraries on what method they prefer and
 the pros/cons to using that authentication method. <u></u><u></u></span></p>
<p class="x_MsoNormal"><span style="font-size:14pt; font-family:Arial,sans-serif; color:black"><u></u> <u></u></span></p>
<p class="x_MsoNormal"><span style="font-size:14pt; color:black">Thanks in advance,<u></u><u></u></span></p>
<p class="x_MsoNormal"><span style="font-size:12pt; color:black"><u></u> <u></u></span></p>
<p class="x_MsoNormal"><span style="font-size:12pt; color:black"><img width="288" height="83" id="x_m_3813174589016739750m_-8778774933866186075Picture_x0020_1" alt="Logo Resized" style="width:3in; height:0.8645in" data-outlook-trace="F:1|T:1" src="cid:ii_1a043ea0d095b006a1"><u></u><u></u></span></p>
<p class="x_MsoNormal"><b><span style="font-size:12pt; color:rgb(89,89,89)"></span></b><b><span style="font-size:12pt; font-family:Arial,sans-serif; color:rgb(38,38,38)">203 Perry Street Wapakoneta, OH 45895<u></u><u></u></span></b></p>
<p class="x_MsoNormal"><b><span style="font-size:12pt; color:rgb(89,89,89)"><u></u> <u></u></span></b></p>
<p class="x_MsoNormal"><b><span style="font-size:14pt; color:rgb(38,38,38)">Fred Miller Jr<u></u><u></u></span></b></p>
<p class="x_MsoNormal"><span style="font-size:14pt; color:black">IT Service Manager<u></u><u></u></span></p>
<p class="x_MsoNormal"><b><span style="font-size:14pt; color:rgb(102,154,102)">T</span></b><span style="font-size:14pt; color:black">:
</span><u><span style="font-size:14pt; color:rgb(26,86,137)">419-738-1215</span></u><span style="font-size:14pt; color:rgb(0,112,192)">
</span><span style="font-size:14pt; color:black">|</span><b><span style="font-size:14pt; color:rgb(102,154,102)"> E</span></b><span style="font-size:14pt; color:black">:
</span><u><span style="font-size:14pt; color:rgb(26,86,137)"><a href="mailto:fmiller@auglaizelibraries.org" target="_blank">fmiller@auglaizelibraries.org</a></span></u><u><span style="font-size:14pt; color:rgb(0,112,192)"><u></u><u></u></span></u></p>
<p class="x_MsoNormal"><span style="color:black"><u></u> <u></u></span></p>
<p class="x_MsoNormal"><u></u> <u></u></p>
</div>
</div>
_______________________________________________<br>
OPLINTECH mailing list<br>
<a href="mailto:OPLINTECH@lists.oplin.org" target="_blank">OPLINTECH@lists.oplin.org</a><br>
<a href="https://lists.oplin.org/mailman/listinfo/oplintech" originalsrc="https://lists.oplin.org/mailman/listinfo/oplintech" rel="noreferrer" target="_blank">https://lists.oplin.org/mailman/listinfo/oplintech</a><br>
<br>
****** Read about the new cybersecurity policy requirements for libraries Learn more at<br>
<a href="https://www.oplin.ohio.gov/security" originalsrc="https://www.oplin.ohio.gov/security" rel="noreferrer" target="_blank">https://www.oplin.ohio.gov/security</a> ******<br>
</div>
</blockquote>
</div>
</div>
</div>
</body>
</html>