[OPLINTECH] *External* Re: Microsoft Office 365 Authentication Changes
Karl Jendretzky
kjendretzky at columbuslibrary.org
Fri Aug 28 10:42:40 EDT 2026
I think Chad is on the right track.
Phishing-resistant authentication is the goal, and passkeys are our best option. Systems relying on rolling codes or number matching are not phishing-resistant. While passkeys are new for users, they are arguably easier to understand: a passkey is something you have rather than something you know, and attackers cannot easily steal a physical device. There's also AiTM safeguards, but that's a technical rabbit hole.
Within Entra, we should require device-bound passkeys (such as Microsoft Authenticator and FIDO2 security keys) to prevent organizational credentials from syncing to personal cloud accounts (like Apple iCloud Keychain or Google Password Manager).
For users unable or unwilling to use a mobile phone, we can provide a security key. We can also deploy contactless NFC readers at shared service points to support tap-to-sign-in for MFA and Windows login.
Yubico Security Key NFC: https://www.amazon.com/dp/B0BVNPWPCN
Contactless Reader: https://www.amazon.com/dp/B079T2FKN1
Windows Hello for Business will serve as a device-bound passkey for our dedicated 1:1 workstations. Users can have multiple independent passkeys to the same Entra account.
Karl Jendretzky | Senior Manager of IT Engineering & Cybersecurity
Columbus Metropolitan Library │ Main Library
96 S. Grant Ave. | Columbus, OH 43215
614.479.3039 office
kjendretzky at columbuslibrary.org | columbuslibrary.org<https://www.columbuslibrary.org/>
________________________________
From: OPLINTECH <oplintech-bounces at lists.oplin.org> on behalf of Chad Neeper via OPLINTECH <oplintech at lists.oplin.org>
Sent: Thursday, August 27, 2026 12:33 PM
To: Fred Miller Jr <fmiller at auglaizelibraries.org>
Cc: oplintech at lists.oplin.org <oplintech at lists.oplin.org>
Subject: *External* Re: [OPLINTECH] Microsoft Office 365 Authentication Changes
EXTERNAL EMAIL WARNING! This email originated from outside of the organization. Use caution with links or attachments unless you trust the sender and know the content is safe. DO NOT PROVIDE YOUR CREDENTIALS!
I've been digging into this myself. While I understand the need... What a pain for a bunch of smaller libraries! I have enough to do already, LOL!
Disclaimer1: I'm no expert in M365 matters. I'm a "Jack-of-all-trades," whereas some people have built entire careers around M$.
Disclaimer2: I've only been using passkeys myself for the past ~5-6 months, but via a more unusual method. I store them in my KeePass password manager and have never actually used a YubiKey or other hardware security key, nor do I use Microsoft Authenticator or another app on my smartphone as a passkey storage device.
From my perspective, this may be a key phrase in Microsoft's announcement: "Move to phishing-resistant authentication before SMS and voice retire"
Also notable is the firm D-Day deadline of February 2027, when SMS/voice will go offline (caveat: unless you're fancy enough to run your own system) and any users configured for that authentication method may be locked out of their account.
MS is strongly preferring phishing-resistant authentication methods. It's probably safe to assume that over time, they'll increasingly discourage other non-phishing-resistant methods besides just the least secure SMS/voice. So, if we have to force the staff to deal with this, we might as well try to stick with methods that aren't next in line to be discouraged. This leaves us with: Passkey (FIDO2), Passkey in Microsoft Authenticator, Windows Hello, and Cert-based authentication. For my own libraries, Windows Hello isn't an option, nor is cert-based auth. That leaves us with Passkey. This means staff will need to use their own smartphone, leveraging Passkeys via Microsoft Authenticator (or some other Passkey app), or they'll need to be issued a library-owned hardware-based USB key. In some cases, an employee may have a library-owned smartphone or another device that could be used for Passkey, but that doesn't really apply to my own libraries.
So, taking this a step further: "Oh crap, I lost my hardware key/smartphone. I can't log in! Help!" (You know it's going to happen.) I'm enabling the Temporary Access Pass (TAP) authentication method too. This allows an admin to issue a one-time-use TAP (in my initial planned configuration) that a user can use to 1) log into their account, and 2) change their authentication methods. This allows them to register a new phone or hardware device. By combining passkey+TAP:
1) Staff use their personal smartphone
2) Staff who can't or refuse to use their personal smartphone can be issued a library-owned hardware security device (e.g., YubiKey).
3) The library can keep just a few extra hardware devices as replacements instead of issuing every user multiple devices (one for primary, another for backup)
If someone sees a fatal flaw in this strategy, I'm all ears!!
______________________________
Chad Neeper
Senior Systems Engineer
Level 9 Networks
740-548-8070 (voice)
866-214-6607 (fax)
Full IT/Computer consulting services -- Specialized in public libraries
On Thu, Aug 27, 2026 at 11:45 AM Fred Miller Jr via OPLINTECH <oplintech at lists.oplin.org<mailto:oplintech at lists.oplin.org>> wrote:
If your library system is using Microsoft Office 365, I would like to hear what some of the libraries around the state are doing regarding changes coming down from Microsoft Office 365 since they are doing away with SMS/Voice authentication in February 2027. I know there are a few alternative authentication methods out there to use, but would like to get some feedback from other libraries on what method they prefer and the pros/cons to using that authentication method.
Thanks in advance,
[Logo Resized]
203 Perry Street Wapakoneta, OH 45895
Fred Miller Jr
IT Service Manager
T: 419-738-1215 | E: fmiller at auglaizelibraries.org<mailto:fmiller at auglaizelibraries.org>
_______________________________________________
OPLINTECH mailing list
OPLINTECH at lists.oplin.org<mailto:OPLINTECH at lists.oplin.org>
https://lists.oplin.org/mailman/listinfo/oplintech
****** Read about the new cybersecurity policy requirements for libraries Learn more at
https://www.oplin.ohio.gov/security ******
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.oplin.org/pipermail/oplintech/attachments/20260828/87375264/attachment.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image002.jpg
Type: image/jpeg
Size: 7497 bytes
Desc: image002.jpg
URL: <http://lists.oplin.org/pipermail/oplintech/attachments/20260828/87375264/attachment.jpg>
More information about the OPLINTECH
mailing list