Hello Alicia,
Here's how my library handles these cases! (FYI, most of our campus infrastructure runs on Microsoft and Ellucian.)
Department accounts: We have these configured as shared email inboxes only, from what I understand. Some external accounts are tied to them (social media and eresources, for example), but nothing on-campus that would require dual auth. This means every staff person (including student employees) needs permissions set in the ILS, LibApps, and Teams, but I think it's worth it to have the individualized audit trails.
Faculty librarian applicants: I've never heard of an institution doing this, but I think it's a great idea.
Community users: We have 3 dedicated computer stations for these users. It doesn't require a login; our IT somehow created a passwordless account exclusively for use on these stations. This means that users effectively share an account, so we have multiple signs posted about logging out of websites. The computers delete files and reset every night. One limitation is that these users can't have their own printing accounts, but that's turned out to be a blessing in disguise.
*
These computers are the only way for community users to access our eresources, since we're on EZProxy and the computers are on the campus IP range. (There's no way for them to access the few databases that require individual accounts, like the NYT.)
*
We previously used Pharos for community user accounts, but quite frankly, it was a pain. At most, we have a few community users a day, so our current setup feels much better scaled to our needs.
Best,
Nathan Sonnenschein (he/him)
User Services & Experience Librarian
Montana State University Billings
________________________________
From: Code for Libraries <CODE4LIB_at_LISTS.CLIR.ORG> on behalf of Alicia Ikerd <aliciaikerd_at_DEPAUW.EDU>
Sent: Wednesday, July 22, 2026 6:55 AM
To: CODE4LIB_at_LISTS.CLIR.ORG <CODE4LIB_at_LISTS.CLIR.ORG>
Subject: [CODE4LIB] Shared Library Accounts & Multi-Factor Authentication
NOTICE: This email originated from outside of your organization. Do not click links, open attachments, or respond unless you were expecting this message and know the content is safe.
Hi Code4Lib Community,
We currently use a handful of shared accounts across our library for
different systems/workflows. As time has passed we've seen an influx of
multi-factor authentication requirements across our accounts/systems. We
inquired with our IT about bypassing or disabling this, but unfortunately,
we cannot. We have successfully tied some department accounts to department
phones. However, we still have a couple of accounts that are more free
floating accounts and thus hard to tie to a specific phone. I've included
some example scenarios below. What are other libraries doing to work around
these MFA issues with shared accounts?
- Faculty Librarian Applicants: In the past we provided a login/password
to applicants so they could access our e-resources off campus when
preparing an instruction presentation. Currently, it would require our team
be available off hours on their personal phones to text a MFA code to an
applicant.
- Community Users: We used to have a user login/password to log a
community patron into and out of a library computer. Now, if we tie it to a
department phone our workers would have to run across the library to
retrieve the MFA phone prompt from the access services phone.
- I'm aware some public libraries use software that generates
temporary usernames/passwords for community borrowers. We do not
have that
software, and acquiring it anytime soon is unlikely.
We would love to hear your workflows and workarounds!
Thanks,
Alicia
--
Alicia Ikerd
Reference and Instruction Librarian
Coordinator of Library Technology
DePauw University
(765) 658-4410
Received on Wed Jul 22 2026 - 10:31:49 EDT