[OPLINTECH] Microsoft Office 365 Authentication Changes

Chad Neeper cneeper at level9networks.com
Thu Aug 27 12:33:03 EDT 2026


I've been digging into this myself. While I understand the need... What a
pain for a bunch of smaller libraries! I have enough to do already, LOL!

Disclaimer1: I'm no expert in M365 matters. I'm a "Jack-of-all-trades,"
whereas some people have built entire careers around M$.
Disclaimer2:  I've only been using passkeys myself for the past ~5-6
months, but via a more unusual method. I store them in my KeePass password
manager and have never actually used a YubiKey or other hardware security
key, nor do I use Microsoft Authenticator or another app on my smartphone
as a passkey storage device.

>From my perspective, this may be a key phrase in Microsoft's announcement:
"Move to *phishing-resistant* authentication before SMS and voice retire"
Also notable is the firm D-Day deadline of February 2027, when SMS/voice
will go offline (caveat: unless you're fancy enough to run your own system)
and any users configured for that authentication method may be locked out
of their account.

MS is strongly preferring *phishing-resistant* authentication methods. It's
probably safe to assume that over time, they'll increasingly discourage
other non-phishing-resistant methods besides just the least secure
SMS/voice. So, if we have to force the staff to deal with this, we might as
well try to stick with methods that aren't next in line to be discouraged.
This leaves us with: Passkey (FIDO2), Passkey in Microsoft Authenticator,
Windows Hello, and Cert-based authentication. For my own libraries, Windows
Hello isn't an option, nor is cert-based auth. That leaves us with Passkey.
This means staff will need to use their own smartphone, leveraging Passkeys
via Microsoft Authenticator (or some other Passkey app), or they'll need to
be issued a library-owned hardware-based USB key. In some cases, an
employee may have a library-owned smartphone or another device that could
be used for Passkey, but that doesn't really apply to my own libraries.

So, taking this a step further:  "Oh crap, I lost my hardware
key/smartphone. I can't log in! Help!"  (You *know* it's going to happen.)
I'm enabling the Temporary Access Pass (TAP) authentication method too.
This allows an admin to issue a one-time-use TAP (in my initial planned
configuration) that a user can use to 1) log into their account, and 2)
change their authentication methods. This allows them to register a new
phone or hardware device. By combining passkey+TAP:
1) Staff use their personal smartphone
2) Staff who can't or refuse to use their personal smartphone can be issued
a library-owned hardware security device (e.g., YubiKey).
3) The library can keep just a few extra hardware devices as replacements
instead of issuing every user multiple devices (one for primary, another
for backup)

If someone sees a fatal flaw in this strategy, I'm all ears!!


______________________________
*Chad Neeper*
Senior Systems Engineer

*Level 9 Networks*
740-548-8070 (voice)
866-214-6607 (fax)

*Full IT/Computer consulting services -- Specialized in public libraries*


On Thu, Aug 27, 2026 at 11:45 AM Fred Miller Jr via OPLINTECH <
oplintech at lists.oplin.org> wrote:

> If your library system is using Microsoft Office 365, I would like to hear
> what some of the libraries around the state are doing regarding changes
> coming down from Microsoft Office 365 since they are doing away with
> SMS/Voice authentication in February 2027. I know there are a few
> alternative authentication methods out there to use, but would like to get
> some feedback from other libraries on what method they prefer and the
> pros/cons to using that authentication method.
>
>
>
> Thanks in advance,
>
>
>
> [image: Logo Resized]
>
> *203 Perry Street Wapakoneta, OH 45895*
>
>
>
> *Fred Miller Jr*
>
> IT Service Manager
>
> *T*: *419-738-1215* |* E*: *fmiller at auglaizelibraries.org
> <fmiller at auglaizelibraries.org>*
>
>
>
>
> _______________________________________________
> OPLINTECH mailing list
> OPLINTECH at lists.oplin.org
> https://lists.oplin.org/mailman/listinfo/oplintech
>
> ****** Read about the new cybersecurity policy requirements for libraries
> Learn more at
> https://www.oplin.ohio.gov/security ******
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.oplin.org/pipermail/oplintech/attachments/20260827/c3884718/attachment.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image002.jpg
Type: image/jpeg
Size: 7497 bytes
Desc: not available
URL: <http://lists.oplin.org/pipermail/oplintech/attachments/20260827/c3884718/attachment.jpg>


More information about the OPLINTECH mailing list