Infinet

Microsoft Is Phasing Out Text-Message MFA. Here’s What Businesses Need to Know 

If you’re used to signing into Microsoft 365 and waiting for a six-digit code to arrive by text, that experience is on its way out. 
Microsoft is moving away from SMS and voice calls as preferred methods of verifying sign-ins and pushing users toward more secure options, including passkeys and the Microsoft Authenticator app. 
For businesses, this is less about learning another Microsoft feature and more about making sure employees are ready before their familiar sign-in option changes.

Why Is Microsoft Moving Away From Text Messages?

Text-message verification was a big improvement over using a password alone. The problem is that attackers have gotten better at getting around it. 
SMS codes can be intercepted or stolen through phishing and SIM-swapping attacks. They also depend on your mobile carrier actually delivering the message. Anyone who has stared at a login screen waiting for a code that never arrives knows that isn’t always a given. 
Microsoft now recommends stronger authentication methods that don’t rely on a text message being sent to your phone. 
That includes Microsoft Authenticator, Windows Hello for Business, security keys and, increasingly, passkeys

Wait — What’s a Passkey?

A passkey is essentially a replacement for a traditional password that uses something you already have, such as your phone or computer, to verify that you’re really you. 
Depending on the device, that might mean using your fingerprint, Face ID, Windows Hello or your device PIN. 
The important part isn’t the terminology. It’s that passkeys are designed to be much harder for an attacker to steal through a fake login page. 
Microsoft Authenticator can also be part of this experience. The app supports MFA approvals, verification codes, passwordless sign-in and passkeys. 

What Is Actually Changing?

Microsoft has been moving users toward stronger authentication for some time, but there are now some important dates for businesses using Microsoft Entra ID. 
Beginning September 1, 2026, Microsoft plans to start automatically enabling passkey registration prompts for users who are still enabled for SMS or voice authentication. 
Then, beginning February 1, 2027, Microsoft-provided SMS and voice authentication will be retired in Microsoft Entra ID. 
That doesn’t mean everyone’s text-message MFA will suddenly disappear tomorrow. Organizations have time to prepare, and Microsoft provides administrators with options for managing the transition. 
But it does mean businesses shouldn’t wait until employees are confronted with an unfamiliar sign-in screen to figure out what they’re supposed to do. 

What Does This Mean for Your Employees? 

For most users, the biggest change will simply be how they prove it’s really them when they sign in
Instead of:
Password → Receive text → Enter six-digit code 
they may use something like: 
Password → Approve sign-in through Authenticator 
or eventually: 
Passkey → Face, fingerprint or device PIN  
Depending on how your Microsoft environment is configured, the exact experience may look different.

And that’s important: businesses shouldn’t tell employees to blindly follow every unexpected authentication prompt they receive. Your IT provider or internal IT team should determine which authentication methods your organization is using and communicate that process to employees.

Why This Is a Good Thing 


Any change to the login process can be annoying at first. From a security standpoint, though, moving away from SMS makes sense. 

Passwords get stolen. Text-message codes can be phished. Attackers routinely create convincing Microsoft login pages designed specifically to capture credentials and verification codes. 

Modern authentication methods make that considerably harder. 

Microsoft is also increasingly using system-preferred authentication, which means that when someone has multiple authentication methods registered, Microsoft can prompt them to use the strongest available option instead of automatically falling back to something weaker.

The goal is pretty simple: make the easiest way to sign in also one of the safest. 

What Should Businesses Do Now? 


You don’t need to panic, and you don’t need to wait until 2027 either. 

This is a good time to have your team review:

Which employees are still using SMS or voice calls for MFA

Whether Microsoft Authenticator is properly configured 

Whether passkeys are appropriate for your organization 

Which authentication methods are allowed in Microsoft Entra ID 

How employees will be notified and trained before their sign-in experience changes 

What your recovery process looks like when someone loses or replaces a phone 

A little preparation now can prevent a lot of “I can’t get into my email” calls later.

MFA Isn’t Going Away — It’s Getting Better


The takeaway isn’t that Microsoft is getting rid of multi-factor authentication. 

Quite the opposite. 

Microsoft is moving away from some of the older ways of doing MFA and toward methods that are harder for attackers to steal, intercept or trick users into handing over.

If your business still relies heavily on text-message codes, now is a good time to review how your Microsoft 365 accounts are protected and start preparing employees for what’s coming. 

Not sure which authentication methods your organization is currently using? InfiNet Solutions can review your Microsoft 365 security configuration, identify users still relying on older authentication methods and help you plan the transition without turning it into a company-wide login headache. 

          Microsoft Is Phasing Out Text-Message MFA. Here’s What Businesses Need to Know  Read More »

          What Happens to Your IT When Your IT Person Leaves 

            It’s a Tuesday afternoon, and the person who’s quietly kept your computers running, your email working, and your printer from catching fire for the last three years just handed you a resignation letter. 
            Maybe it’s your “IT guy,” the one person who wears six hats and IT happens to be one of them. Maybe it’s the office manager who “just kind of became” the tech person because she was good with computers. Either way, your stomach drops a little, because you realize you have no idea what they actually do all day, let alone how to replace them. 
            This isn’t a story about one employee being irreplaceable. It’s a story about what happens to a business when all of its IT knowledge lives in one person’s head, and what to do about it before you’re staring down a two-week countdown. 
            When that person walks out the door, a few things tend to surface all at once: 
            • Passwords and admin access nobody else has. Server logins, router credentials, the admin account for your accounting software 
            • Vendor relationships with no paper trail. Your internet provider, your line-of-business software support line, your phone system vendor: this person knew who to call and how to get things done. That relationship doesn’t automatically transfer. 
            • Undocumented systems. Why does that one server reboot every Sunday at 2 a.m.?  
            • Backup and disaster recovery knowledge. What is being backed up? Are they running, how do they work, how often do they run, where do the backups live, is it 
            • A hundred small “how do I…” answers that used to take thirty seconds and now take a frantic afternoon of trial and error. 
            Downtime is an obvious risk: something goes wrong and nobody knows how to fix it quickly. Security can become another problem. If a departing employee’s access isn’t fully accounted for, the business can be left with accounts that should have been disabled, shared credentials that were never rotated, or admin access nobody has reviewed. Those are avoidable gaps, but only if someone owns the offboarding checklist. 
            There’s also hiring pressure. When nobody else can cover the work, it’s easy to feel rushed into a replacement decision because every week without dependable IT coverage feels risky.
            The fix isn’t complicated, but it does take intention: 
            • Document the environment. Not a novel, just a living reference of what systems and software exist, who the vendors are, where business-controlled admin access lives, and how backups and recovery work. This should exist whether or not anyone is planning to leave. 
            • Use a business-managed password manager, not a sticky note or a personal vault only one person can access. Important credentials should be stored so the business can recover them without depending on the person who created them. 
            • Build in redundancy. Even a small operation benefits from more than one person understanding the basics of how things run, or from a partner who already does. 
            • Treat IT offboarding like any other offboarding. When someone with system access leaves, reviewing and removing that access should be a standard checklist item, not an afterthought. 
            If you’re reading this because someone just gave notice, start with a list of every system, login, vendor, and recurring task they touch. Make sure the business controls the admin accounts and password vaults. While they’re still available to help, document backup and recovery steps, vendor contacts, and any unusual workarounds. When their access is no longer needed, disable their individual accounts and rotate any shared credentials they knew as part of offboarding. None of this needs to be adversarial. Most departing employees are glad to leave things in good shape if someone simply asks. 
            Need help making the handoff simpler? Let’s talk. 
            Start by capturing business-controlled admin access, vendor contacts, system details, and recurring IT tasks before the employee leaves. Then review and disable access that is no longer needed so someone else can keep the environment running without relying on one person’s memory. 
            Keep an up-to-date record of systems, vendors, admin access, backup and recovery steps, and recurring tasks. Make sure at least one other person or outside partner can get to that information when it’s needed. 
            IT documentation is a written record of your business’s systems, access, vendors, and processes, including how the network is set up, how backups are recovered, and who to call for support. It gives the next person a usable starting point instead of forcing them to rebuild everything from memory. 
            It depends on your environment, workload, budget, and how much day-to-day coverage you need. A second employee adds internal capacity; a managed IT provider can add broader coverage, depth of knowledge and strategy without another full-time hire. 
            Review every system, application, admin account, password vault, and vendor portal they can access. Disable their individual access when it is no longer needed, transfer ownership of business accounts, and rotate any shared credentials they knew.  
            At minimum, keep a current list of systems and software, vendor contacts, business-controlled admin access, backup and recovery steps, and the recurring tasks someone else would need to take over. It doesn’t need to be exhaustive. It needs to be useful enough that someone unfamiliar with the environment can step in without starting from scratch.

            What Happens to Your IT When Your IT Person Leaves  Read More »

            HIPAA Compliance Isn’t a Checkbox. Here’s What Omaha Healthcare Practices Actually Need to Do. 

            Your practice manager forwards you an email: your insurance carrier wants documentation of your latest HIPAA Security Risk Analysis. You start looking. What you find is a training certificate from a few years ago, a privacy policy saved in a shared folder, and a vendor agreement nobody is sure is current. 
            What you do not find is a clear record showing how your practice identifies security risks, addresses them, and reviews its safeguards over time. 
            That is where many dental, eye care, and medical practices get stuck. HIPAA compliance is not a certificate you earn once. It is an ongoing process built around documented policies, staff responsibilities, technology safeguards, vendor oversight, and incident planning. 
            For day-to-day operations, three HIPAA rules matter most. The Privacy Rule governs how protected health information may be used and disclosed. The Security Rule applies to electronic protected health information, or ePHI. The Breach Notification Rule explains what regulated organizations must do after certain breaches of unsecured information. 
            In a healthcare practice, ePHI may be stored or transmitted through practice management software, billing systems, email, cloud applications, workstations, mobile devices, backups, and diagnostic imaging. Panoramic dental images, X-rays, retina scans, and intraoral photos can be protected health information just like chart notes and billing records. 
            A workable compliance program should include: 
            • A documented Security Risk Analysis that reflects the current environment 
            • Written privacy and security policies staff can follow 
            • Role-based training that is updated when systems or procedures change 
            • Business Associate Agreements where the vendor relationship requires one 
            • A breach response plan with clear responsibilities and escalation steps 
            The goal is not paperwork for its own sake. It is to protect patient information and be able to show how the practice manages risk when an insurer, auditor, or regulator asks. 
            A Security Risk Analysis, or SRA, is the foundation of the HIPAA Security Rule’s risk-management process. It identifies where the practice creates, receives, maintains, or transmits ePHI and evaluates the threats and vulnerabilities that could affect that information. 
            The analysis should cover the full environment, not only a list of computers. That may include practice management and imaging systems, email, remote access, front-desk devices, connected equipment, cloud platforms, backups, third-party integrations, and staff access from mobile or personal devices. 
            The current Security Rule does not set one required schedule for every organization. HHS describes risk analysis as an ongoing process. Many practices use an annual review as a practical baseline, with additional review after a security incident or a meaningful change in technology, staffing, vendors, ownership, or operations. 
            A useful SRA should lead to action. Each significant finding should have a planned response, a responsible owner, a target date, and a way to confirm that the issue was addressed. 
            HIPAA does not require every practice to use the same products or build the same technology environment. It does require reasonable and appropriate administrative, physical, and technical safeguards based on the risks the practice identifies. 
            Common areas to review include: 
            • Individual accounts and role-based access, rather than shared logins 
            • Prompt access changes when an employee changes roles or leaves 
            • Multi-factor authentication for email, remote access, cloud services, and administrative accounts 
            • Encryption decisions that are based on risk and documented in writing 
            • Backups that are protected, tested, and recoverable 
            • System monitoring with clear ownership for reviewing and escalating alerts 
            Under the current rule, encryption is an addressable implementation specification. Addressable does not mean optional. A practice must determine whether encryption is reasonable and appropriate, document that decision, and use an equivalent alternative when appropriate. The same practical review should cover both stored information and data sent through email, file transfers, portals, or system integrations. 
            Backups also need more than a successful status message. Recovery testing should confirm that patient records, schedules, images, and billing data can be restored after an outage or security incident. 
            A Business Associate Agreement, or BAA, is generally required when a vendor creates, receives, maintains, or transmits protected health information while performing services on behalf of a covered entity. 
            Depending on the services provided, that may include a billing company, cloud hosting provider, practice management vendor, document destruction company, consultant, or IT service provider. Not every company that works with a practice is automatically a business associate; the deciding factor is what the vendor does and whether the service involves PHI. 
            Review the vendor list regularly and confirm which relationships require a BAA, whether each agreement is signed and current, and whether relevant subcontractors are covered. A BAA documents responsibilities, but it does not replace basic due diligence about how the vendor protects information and reports incidents. 
            HHS proposed a major update to the HIPAA Security Rule in December 2024, and the proposal was published in January 2025. As of August 2026, it has not been finalized, so the current Security Rule remains in effect. 
            The proposal would remove the distinction between required and addressable implementation specifications and add more specific requirements for areas such as multi-factor authentication, encryption, asset inventories, network maps, compliance audits, vulnerability testing, incident response, and business associate verification. 
            The federal Unified Agenda currently lists July 2027 as the anticipated date for final action. That is an agency planning estimate, not a guaranteed publication date or compliance deadline. The final requirements and timing could still change. 
            One change is already in effect. As of February 16, 2026, covered healthcare providers and health plans are required to include applicable information about substance use disorder patient records under 42 CFR Part 2 in their Notices of Privacy Practices. Practices should confirm that their current notice contains the required language and is posted or distributed where required. 
            The practical approach is to address known risks now without treating a proposal as current law. Improvements such as stronger account protection, tested recovery, current documentation, and clear vendor oversight reduce risk today and make future changes easier to manage. 
            An IT provider should not replace your attorney, privacy officer, or compliance advisor. Its role is to manage and document the technology that supports the compliance program. 
            A qualified provider should understand which systems contain ePHI, how access is controlled, how backups are protected, how security alerts are handled, and how the practice will recover after an incident. The provider should also be prepared to sign a BAA when its services make it a business associate. 
            InfiNet’s Managed IT Services can support ongoing technology management, while Cyber Security Solutions and IT Support for Healthcare provide relevant security and healthcare-focused context. 
            HIPAA compliance should be reflected in the way the practice manages information every day. When policies, technology, vendors, and staff procedures support one another, the work becomes more manageable and the practice is better prepared when questions arise. 
            Need help making the technology side of HIPAA easier to manage? Let’s talk. 
            An SRA documents where ePHI exists, the threats and vulnerabilities that affect it, and the level of risk. The current rule does not prescribe one fixed schedule. Review frequency should reflect the practice’s environment, with updates when significant changes or incidents affect ePHI. 
            Generally, yes, when the provider creates, receives, maintains, or transmits PHI while performing services for the practice. The answer depends on the actual service relationship and access to PHI. 
            Yes. Diagnostic images maintained as part of a patient’s record can be PHI. When stored or transmitted electronically, they are subject to the Security Rule’s protections for ePHI. 
            Common gaps include incomplete risk analysis, outdated access lists, missing vendor documentation, weak account protection, untested recovery plans, and policies that no longer match how the practice actually works. 
            The Notice of Privacy Practices change tied to 42 CFR Part 2 took effect on February 16, 2026. The proposed Security Rule overhaul remains pending as of August 2026, and July 2027 is only the current anticipated date for final action. 
            Outcomes depend on the facts and may include technical assistance, corrective action, monitoring, a settlement, or a civil monetary penalty. Clear documentation and timely remediation help a practice explain what happened and how it responded. 
            Yes. Monitoring can help identify failed backups, suspicious logins, disabled security tools, unauthorized changes, and other technical issues. It supports compliance when alerts are reviewed, documented, and connected to a response process. 

            HIPAA Compliance Isn’t a Checkbox. Here’s What Omaha Healthcare Practices Actually Need to Do.  Read More »

            Security Awareness Training That Actually Works (Without Being Annoying) 

            It’s the third Tuesday of the quarter, and an email lands in every inbox with the subject line, “Mandatory Security Training – Complete by Friday.” You can practically hear the collective groan roll through the office. 
            Everyone clicks through the slides, guesses their way through the quiz, and moves on with the day. Then a convincing invoice request arrives two months later, and the employee facing it has never practiced what to do in that moment. 
            If that sounds familiar, you have not failed at cybersecurity. You may simply be relying on a training model designed to document completion instead of build better habits. For businesses in Omaha, Lincoln, and Council Bluffs, the goal is not to make employees cybersecurity experts. It is to help them recognize suspicious activity, slow down, and report it quickly. 
            A long annual presentation may satisfy an administrative requirement, but it gives employees very little practice. The Federal Trade Commission recommends reinforcing security messages with periodic refreshers and updates, rather than treating training as a one-time event. 
            Most employees are moving quickly, switching between tasks, answering customers, approving invoices, and trying to keep work on schedule. A realistic phishing message is designed to take advantage of that pace. 
            The 2026 Verizon Data Breach Investigations Report found that the non-intentional human element was present in 62% of breaches. That does not mean people are the only security problem. It does mean employee decisions remain an important part of the risk picture, alongside technical weaknesses and criminal tactics. 
            A large 2026 benchmark from KnowBe4 shows what repeated practice can change. The report analyzed 42 million simulated phishing tests across 14.8 million users at 64,000 organizations. Its average Phish-prone Percentage was 33.2% before training, 20.1% after 90 days, and 4.2% after one year of ongoing training and testing. These are vendor customer benchmarks, so every organization will not see identical results, but the direction is clear: consistent practice is more useful than a once-a-year reminderView the 2026 benchmark source. 
            Security awareness is not a course employees finish once. It is a set of habits the organization reinforces, and leadership sets the tone. 
            • Leadership participates. Owners and managers complete the same training and follow the same verification steps as everyone else. 
            • Reporting is treated as a win. Thank employees who flag suspicious messages, even when the message turns out to be legitimate. 
            • High-risk requests get a second check. Wire transfers, payroll changes, gift card requests, and unusual account updates should be verified through a known phone number or established process, not by replying to the message. 
            • Security habits stay visible. Password manager use, careful review of multi-factor authentication prompts, safe handling of personal devices, and quick reporting should appear in regular reminders and team conversations. 
            Done well, this stops feeling like another training assignment. It becomes part of how the team works. 
            A completion percentage tells you who opened the training. It does not tell you whether employees are becoming faster or more confident at recognizing risk. 
            • Phishing engagement rate. How many employees clicked, opened an attachment, entered information, or otherwise interacted with a simulation? 
            • Reporting rate. How many employees used the reporting process, and how quickly did they report? 
            • Repeat behavior. Are the same people making the same mistake, or are they improving after coaching? 
            • Simulation difficulty. Was the test easy, moderate, or difficult for the intended audience? Use that context before comparing one campaign with another. 
            The goal is not a perfect score. The goal is steady improvement and faster reporting when something looks wrong. 
            Security awareness training is just one piece of a comprehensive cybersecurity strategy. The most effective organizations take a layered approach that combines people, processes, and technology to reduce risk and improve resilience. 
            A trusted managed IT partner should help implement and maintain the technical safeguards that support your business, including: 
            • Identity and access management  
            • Endpoint protection  
            • Email security  
            • Regular patching   
            • Secure backups  
            • Continuous monitoring  
            • Vulnerability management  
            • Incident response plan.  
            Together, these layers help prevent attacks, limit their impact, and support a faster recovery when incidents occur. 
            Technology alone isn’t enough, and neither is training alone. Lasting cybersecurity comes from combining informed employees with well-designed systems, thoughtful policies, and ongoing guidance that evolves alongside today’s threats. The result is a security program that protects your business without getting in the way of the people who keep it running. 
            There is no universal schedule for every business. A practical starting point is short monthly refreshers paired with regular simulated phishing tests, then adjust the cadence based on employee roles, risk, and results. The important part is consistent reinforcement, not one long annual session. 
            It can, when it is part of an ongoing program. In KnowBe4’s 2026 customer benchmark, the average Phish-prone Percentage moved from 33.2% before training to 20.1% after 90 days and 4.2% after one year of training and testing. Those results are not a guarantee for every organization, but they support the value of repeated practice and measurement. See the source data. 
            Provide quick, private, judgment-free coaching. Explain the clues in the message, show the correct reporting process, and give the employee a chance to practice again. Public callouts can make people less willing to report a real mistake. 
            Results vary, but the KnowBe4 benchmark showed a measurable change within the first 90 days and a much lower average engagement rate after one year. Track your own baseline and trend instead of assuming a published benchmark will match your organization exactly. 
            Requirements vary by industry, framework, contract, and insurance policy. A slide deck may document that training occurred, but it may not satisfy requirements for recurring education, testing, reporting, or proof of completion. Confirm the exact requirements that apply to your business with the appropriate compliance, legal, or insurance resource. 
            Include password and multi-factor authentication habits, payment and payroll verification, safe use of personal devices, handling of sensitive information, physical security, and how to respond to suspicious texts, phone calls, collaboration messages, or AI-generated impersonation attempts. 
            No. Training reduces avoidable mistakes, but it does not replace technical protections. The strongest approach combines employee awareness with multi-factor authentication, secure email controls, monitored backups, patching, endpoint protection, and proactive network monitoring. 

            Security Awareness Training That Actually Works (Without Being Annoying)  Read More »

            Your Employees Are Using Personal Phones for Work. Here’s What That Actually Means.

            It’s Already Happening

            Nobody sent a memo. Nobody asked for permission. It happened organically – the way most technology habits do. 

            Your team got busy. Checking work email from a personal phone was easier than carrying two devices. Responding to a Teams message from the couch felt like being a good employee. Downloading a company file to finish a presentation seemed harmless enough. 

            And honestly? Most of the time, it seems fine. 

            It isn’t. 

            This is not an argument for banning personal phones. Flexible access to work tools is part of how modern businesses operate, and employees are not doing anything wrong simply by checking work email on a phone they already own. 

            But personal access changes what your business can see, manage, and remove. A few practical safeguards can reduce that risk without forcing everyone to carry two phones. 

            What’s Actually at Risk

            Company Data on a Device You Don’t Control 

            When an employee adds company email, Teams, SharePoint, or another business app to a personal phone, company information is being accessed from a device the business does not own or manage. 

            That phone may use a weak passcode, back up information to a personal cloud account, be shared with a family member, or include apps your IT team has never reviewed. The exact risk depends on the device, the apps, and how access is configured, but the business has less visibility than it would with a company-managed device. 

            The Departing Employee Problem 

            When an employee leaves, what happens to the company data and active sessions on that person’s phone? 

            With the right mobile device or app-management setup, IT may be able to revoke access and selectively remove company data while leaving personal photos, messages, and apps alone. Without that setup, the business may be limited to changing passwords, revoking sessions, and hoping local copies were not saved elsewhere. 

            That is why the policy and technology need to be in place before offboarding begins – not after access has already walked out the door. 

            A Lost Phone Can Become a Business Issue 

            A phone left in a rideshare can become a security concern if it still has active access to company email, files, or internal systems. 

            A screen lock, automatic timeout, and multi-factor authentication all help. MFA adds another layer beyond the password, and phishing-resistant methods provide stronger protection than text-message codes alone. It does not eliminate every risk, especially if a device is already unlocked or a session has been compromised, but it makes account takeover much harder. 

            Personal Apps Add Another Variable 

            Personal phones usually contain more apps than company-managed devices. Mobile operating systems are designed to separate apps, but malicious software, risky permissions, stolen credentials, and unpatched vulnerabilities can still create exposure. 

            The point is not that every personal app is dangerous. It is that the company cannot evaluate or manage the full device unless the employee has agreed to an appropriate management approach. 

            The Fix Is Not “No Personal Phones” 

            The goal is not to make employees carry two phones or feel monitored. The goal is to protect company information while respecting personal privacy. 

            A written BYOD policy – “Bring Your Own Device” – is the starting point. It should explain which company apps and data may be used on personal devices, what security settings are required, how lost devices must be reported, what happens during offboarding, and what the company can and cannot manage. 

            Require a PIN, passcode, or biometric lock on every phone that accesses company accounts. The device should also lock automatically after a reasonable period of inactivity. 

            Enable multi-factor authentication on Microsoft 365 and other core business applications. Where practical, use phishing-resistant options such as passkeys, security keys, or certificate-based authentication rather than relying only on SMS codes. 

            Use mobile device management or mobile application management when the business needs more control. Depending on the platform and configuration, these tools can separate work data from personal data, apply security rules to company apps, block access from noncompliant devices, and remove managed business data without factory-resetting the entire phone. 

            What “Having a Policy” Actually Looks Like 

            For an Omaha-area business with 25-100 employees, a practical starting point can be simple: 

            • A one-page BYOD policy employees review and acknowledge during onboarding. 
            • A screen-lock requirement for any device that accesses company accounts. 
            • Multi-factor authentication on Microsoft 365, email, and other core applications. 
            • A clear lost-or-stolen-device reporting process. 
            • An offboarding checklist that revokes accounts, sessions, and device access promptly. 

            A defined management approach for company data, including whether selective removal is available. 

            This does not have to become a massive IT project. It is a baseline that gives employees clear expectations and gives the business a better response when a phone is lost, replaced, or no longer used for work. 

            Because privacy, employment, and consent requirements can vary, the final policy should be reviewed with HR or legal counsel before it is rolled out. 

            The Conversation Worth Having

            If you are not sure which personal devices currently have access to company email, Teams, SharePoint, your CRM, or project management tools, start with an access and device review. 

            Microsoft 365 and other business platforms can provide device and sign-in information, but what administrators can see depends on the licensing, enrollment method, and management tools already in place. 

            InfiNet helps businesses throughout Omaha, Lincoln, Council Bluffs, and surrounding communities understand what is connected, choose an approach that fits the business, and put practical policies in place. 

            Not sure which personal devices can access your systems? Let’s talk. 

            Frequently Asked Questions

            Is it safe for employees to use personal phones for work email? 

            It can be, when the business requires a screen lock, uses MFA, limits access appropriately, and has a written process for lost devices and offboarding. The right setup depends on the sensitivity of the data and how much control the business needs. 

            What is a BYOD policy? 

            BYOD stands for “Bring Your Own Device.” A BYOD policy explains how employees may use personal devices for work, which security requirements apply, how incidents must be reported, and what happens to company access and data when employment ends. 

            Can my company remove data from an employee’s personal phone? 

            Possibly. Mobile app management can be configured to remove managed company data from supported apps, while device-management tools may offer broader actions. The available options depend on the platform, enrollment method, licensing, and policy. The company should document the approach clearly and obtain appropriate HR or legal guidance. 

            What happens if a personal phone with work access is lost or stolen? 

            The employee should report it immediately. IT can revoke active sessions, reset credentials when appropriate, remove managed company data if the technology supports it, and review sign-in activity for unusual access. A screen lock and MFA reduce the risk, but the response process still matters. 

            How do I find out which personal devices have access? 

            Start with the administration tools for Microsoft 365 and your other core applications. Managed or enrolled devices may appear with details such as operating system, management status, and last check-in. Sign-in logs can provide additional context for devices that are not formally managed. 

            Do employees have to give up privacy to use a personal phone for work? 

            Not necessarily. Mobile application management can leave the personal device under the employee’s control while applying policies only to supported company apps and data. The exact visibility and control should be explained in the BYOD policy so employees understand what the business can and cannot 

            Your Employees Are Using Personal Phones for Work. Here’s What That Actually Means. Read More »

            Talk to our Team