Re: Shared Library Accounts & Multi-Factor Authentication

From: Mike Rylander <mrylander_at_nyob>
Date: Thu, 23 Jul 2026 14:01:30 -0400
To: CODE4LIB_at_LISTS.CLIR.ORG
Hi,

In addition to attaching multiple physical devices (Yubi keys, browser
passkeys, etc) as second factors on an account, if you use Google
Authenticator for TOTP you can export entries as a QR code for
transfer to another phone.  This essentially allows you to duplicate
the underlying secret to another person's authenticator app on demand,
though it is definitely not streamlined for this purpose.  Other TOTP
apps may make this simpler, but I haven't looked into that
specifically.

Regards,

--
Mike Rylander
Research and Development Manager
Equinox Open Library Initiative
1-877-OPEN-ILS (673-6457)
work: miker_at_equinoxOLI.org
personal: mrylander_at_gmail.com
https://equinoxOLI.org

On Thu, Jul 23, 2026 at 1:34 PM Matthew Murray
<000002b67a874033-dmarc-request_at_lists.clir.org> wrote:
>
> Does your IT department/MFA system support physical security keys? (Like Yubikeys or Duo physical tokens.) These have their own limitations, but wouldn't be tied to a specific phone so may help in some of your scenarios.
>
> Best,
> Matthew Murray (he/they)
> Data Librarian, Teaching Assistant Professor
> Center for Research Data & Digital Scholarship
> University Libraries
> University of Colorado Boulder
> Matthew.Murray-2_at_colorado.edu
> orcid.org/0000-0001-5799-8471
>
> I support undocumented students, staff, and their families.
>
> CU Boulder acknowledges that it is located on the traditional territories and ancestral homelands of the Cheyenne, Arapaho, Ute, and many other Indigenous nations.
>
> -----Original Message-----
> From: Code for Libraries <CODE4LIB_at_LISTS.CLIR.ORG> On Behalf Of CODE4LIB automatic digest system
>
> Date:    Wed, 22 Jul 2026 08:55:45 -0400
> From:    Alicia Ikerd <aliciaikerd_at_DEPAUW.EDU>
> Subject: Shared Library Accounts & Multi-Factor Authentication
>
> Hi Code4Lib Community,
>
> We currently use a handful of shared accounts across our library for different systems/workflows. As time has passed we've seen an influx of multi-factor authentication requirements across our accounts/systems. We inquired with our IT about bypassing or disabling this, but unfortunately, we cannot. We have successfully tied some department accounts to department phones. However, we still have a couple of accounts that are more free floating accounts and thus hard to tie to a specific phone. I've included some example scenarios below. What are other libraries doing to work around these MFA issues with shared accounts?
>
>    - Faculty Librarian Applicants: In the past we provided a login/password
>    to applicants so they could access our e-resources off campus when
>    preparing an instruction presentation. Currently, it would require our team
>    be available off hours on their personal phones to text a MFA code to an
>    applicant.
>    - Community Users: We used to have a user login/password to log a
>    community patron into and out of a library computer. Now, if we tie it to a
>    department phone our workers would have to run across the library to
>    retrieve the MFA phone prompt from the access services phone.
>       - I'm aware some public libraries use software that generates
>       temporary usernames/passwords for community borrowers. We do not have that
>       software, and acquiring it anytime soon is unlikely.
>
> We would love to hear your workflows and workarounds!
>
> Thanks,
> Alicia
> --
> Alicia Ikerd
> Reference and Instruction Librarian
> Coordinator of Library Technology
> DePauw University
> (765) 658-4410
Received on Thu Jul 23 2026 - 14:01:28 EDT