Blog

Microsoft Is Phasing Out Text-Message MFA. Here’s What Businesses Need to Know 

If you’re used to signing into Microsoft 365 and waiting for a six-digit code to arrive by text, that experience is on its way out. 
Microsoft is moving away from SMS and voice calls as preferred methods of verifying sign-ins and pushing users toward more secure options, including passkeys and the Microsoft Authenticator app. 
For businesses, this is less about learning another Microsoft feature and more about making sure employees are ready before their familiar sign-in option changes.

Why Is Microsoft Moving Away From Text Messages?

Text-message verification was a big improvement over using a password alone. The problem is that attackers have gotten better at getting around it. 
SMS codes can be intercepted or stolen through phishing and SIM-swapping attacks. They also depend on your mobile carrier actually delivering the message. Anyone who has stared at a login screen waiting for a code that never arrives knows that isn’t always a given. 
Microsoft now recommends stronger authentication methods that don’t rely on a text message being sent to your phone. 
That includes Microsoft Authenticator, Windows Hello for Business, security keys and, increasingly, passkeys

Wait — What’s a Passkey?

A passkey is essentially a replacement for a traditional password that uses something you already have, such as your phone or computer, to verify that you’re really you. 
Depending on the device, that might mean using your fingerprint, Face ID, Windows Hello or your device PIN. 
The important part isn’t the terminology. It’s that passkeys are designed to be much harder for an attacker to steal through a fake login page. 
Microsoft Authenticator can also be part of this experience. The app supports MFA approvals, verification codes, passwordless sign-in and passkeys. 

What Is Actually Changing?

Microsoft has been moving users toward stronger authentication for some time, but there are now some important dates for businesses using Microsoft Entra ID. 
Beginning September 1, 2026, Microsoft plans to start automatically enabling passkey registration prompts for users who are still enabled for SMS or voice authentication. 
Then, beginning February 1, 2027, Microsoft-provided SMS and voice authentication will be retired in Microsoft Entra ID. 
That doesn’t mean everyone’s text-message MFA will suddenly disappear tomorrow. Organizations have time to prepare, and Microsoft provides administrators with options for managing the transition. 
But it does mean businesses shouldn’t wait until employees are confronted with an unfamiliar sign-in screen to figure out what they’re supposed to do. 

What Does This Mean for Your Employees? 

For most users, the biggest change will simply be how they prove it’s really them when they sign in
Instead of:
Password → Receive text → Enter six-digit code 
they may use something like: 
Password → Approve sign-in through Authenticator 
or eventually: 
Passkey → Face, fingerprint or device PIN  
Depending on how your Microsoft environment is configured, the exact experience may look different.

And that’s important: businesses shouldn’t tell employees to blindly follow every unexpected authentication prompt they receive. Your IT provider or internal IT team should determine which authentication methods your organization is using and communicate that process to employees.

Why This Is a Good Thing 


Any change to the login process can be annoying at first. From a security standpoint, though, moving away from SMS makes sense. 

Passwords get stolen. Text-message codes can be phished. Attackers routinely create convincing Microsoft login pages designed specifically to capture credentials and verification codes. 

Modern authentication methods make that considerably harder. 

Microsoft is also increasingly using system-preferred authentication, which means that when someone has multiple authentication methods registered, Microsoft can prompt them to use the strongest available option instead of automatically falling back to something weaker.

The goal is pretty simple: make the easiest way to sign in also one of the safest. 

What Should Businesses Do Now? 


You don’t need to panic, and you don’t need to wait until 2027 either. 

This is a good time to have your team review:

Which employees are still using SMS or voice calls for MFA

Whether Microsoft Authenticator is properly configured 

Whether passkeys are appropriate for your organization 

Which authentication methods are allowed in Microsoft Entra ID 

How employees will be notified and trained before their sign-in experience changes 

What your recovery process looks like when someone loses or replaces a phone 

A little preparation now can prevent a lot of “I can’t get into my email” calls later.

MFA Isn’t Going Away — It’s Getting Better


The takeaway isn’t that Microsoft is getting rid of multi-factor authentication. 

Quite the opposite. 

Microsoft is moving away from some of the older ways of doing MFA and toward methods that are harder for attackers to steal, intercept or trick users into handing over.

If your business still relies heavily on text-message codes, now is a good time to review how your Microsoft 365 accounts are protected and start preparing employees for what’s coming. 

Not sure which authentication methods your organization is currently using? InfiNet Solutions can review your Microsoft 365 security configuration, identify users still relying on older authentication methods and help you plan the transition without turning it into a company-wide login headache. 

          Microsoft Is Phasing Out Text-Message MFA. Here’s What Businesses Need to Know  Read More »

          HIPAA Compliance Isn’t a Checkbox. Here’s What Omaha Healthcare Practices Actually Need to Do. 

          Your practice manager forwards you an email: your insurance carrier wants documentation of your latest HIPAA Security Risk Analysis. You start looking. What you find is a training certificate from a few years ago, a privacy policy saved in a shared folder, and a vendor agreement nobody is sure is current. 
          What you do not find is a clear record showing how your practice identifies security risks, addresses them, and reviews its safeguards over time. 
          That is where many dental, eye care, and medical practices get stuck. HIPAA compliance is not a certificate you earn once. It is an ongoing process built around documented policies, staff responsibilities, technology safeguards, vendor oversight, and incident planning. 
          For day-to-day operations, three HIPAA rules matter most. The Privacy Rule governs how protected health information may be used and disclosed. The Security Rule applies to electronic protected health information, or ePHI. The Breach Notification Rule explains what regulated organizations must do after certain breaches of unsecured information. 
          In a healthcare practice, ePHI may be stored or transmitted through practice management software, billing systems, email, cloud applications, workstations, mobile devices, backups, and diagnostic imaging. Panoramic dental images, X-rays, retina scans, and intraoral photos can be protected health information just like chart notes and billing records. 
          A workable compliance program should include: 
          • A documented Security Risk Analysis that reflects the current environment 
          • Written privacy and security policies staff can follow 
          • Role-based training that is updated when systems or procedures change 
          • Business Associate Agreements where the vendor relationship requires one 
          • A breach response plan with clear responsibilities and escalation steps 
          The goal is not paperwork for its own sake. It is to protect patient information and be able to show how the practice manages risk when an insurer, auditor, or regulator asks. 
          A Security Risk Analysis, or SRA, is the foundation of the HIPAA Security Rule’s risk-management process. It identifies where the practice creates, receives, maintains, or transmits ePHI and evaluates the threats and vulnerabilities that could affect that information. 
          The analysis should cover the full environment, not only a list of computers. That may include practice management and imaging systems, email, remote access, front-desk devices, connected equipment, cloud platforms, backups, third-party integrations, and staff access from mobile or personal devices. 
          The current Security Rule does not set one required schedule for every organization. HHS describes risk analysis as an ongoing process. Many practices use an annual review as a practical baseline, with additional review after a security incident or a meaningful change in technology, staffing, vendors, ownership, or operations. 
          A useful SRA should lead to action. Each significant finding should have a planned response, a responsible owner, a target date, and a way to confirm that the issue was addressed. 
          HIPAA does not require every practice to use the same products or build the same technology environment. It does require reasonable and appropriate administrative, physical, and technical safeguards based on the risks the practice identifies. 
          Common areas to review include: 
          • Individual accounts and role-based access, rather than shared logins 
          • Prompt access changes when an employee changes roles or leaves 
          • Multi-factor authentication for email, remote access, cloud services, and administrative accounts 
          • Encryption decisions that are based on risk and documented in writing 
          • Backups that are protected, tested, and recoverable 
          • System monitoring with clear ownership for reviewing and escalating alerts 
          Under the current rule, encryption is an addressable implementation specification. Addressable does not mean optional. A practice must determine whether encryption is reasonable and appropriate, document that decision, and use an equivalent alternative when appropriate. The same practical review should cover both stored information and data sent through email, file transfers, portals, or system integrations. 
          Backups also need more than a successful status message. Recovery testing should confirm that patient records, schedules, images, and billing data can be restored after an outage or security incident. 
          A Business Associate Agreement, or BAA, is generally required when a vendor creates, receives, maintains, or transmits protected health information while performing services on behalf of a covered entity. 
          Depending on the services provided, that may include a billing company, cloud hosting provider, practice management vendor, document destruction company, consultant, or IT service provider. Not every company that works with a practice is automatically a business associate; the deciding factor is what the vendor does and whether the service involves PHI. 
          Review the vendor list regularly and confirm which relationships require a BAA, whether each agreement is signed and current, and whether relevant subcontractors are covered. A BAA documents responsibilities, but it does not replace basic due diligence about how the vendor protects information and reports incidents. 
          HHS proposed a major update to the HIPAA Security Rule in December 2024, and the proposal was published in January 2025. As of August 2026, it has not been finalized, so the current Security Rule remains in effect. 
          The proposal would remove the distinction between required and addressable implementation specifications and add more specific requirements for areas such as multi-factor authentication, encryption, asset inventories, network maps, compliance audits, vulnerability testing, incident response, and business associate verification. 
          The federal Unified Agenda currently lists July 2027 as the anticipated date for final action. That is an agency planning estimate, not a guaranteed publication date or compliance deadline. The final requirements and timing could still change. 
          One change is already in effect. As of February 16, 2026, covered healthcare providers and health plans are required to include applicable information about substance use disorder patient records under 42 CFR Part 2 in their Notices of Privacy Practices. Practices should confirm that their current notice contains the required language and is posted or distributed where required. 
          The practical approach is to address known risks now without treating a proposal as current law. Improvements such as stronger account protection, tested recovery, current documentation, and clear vendor oversight reduce risk today and make future changes easier to manage. 
          An IT provider should not replace your attorney, privacy officer, or compliance advisor. Its role is to manage and document the technology that supports the compliance program. 
          A qualified provider should understand which systems contain ePHI, how access is controlled, how backups are protected, how security alerts are handled, and how the practice will recover after an incident. The provider should also be prepared to sign a BAA when its services make it a business associate. 
          InfiNet’s Managed IT Services can support ongoing technology management, while Cyber Security Solutions and IT Support for Healthcare provide relevant security and healthcare-focused context. 
          HIPAA compliance should be reflected in the way the practice manages information every day. When policies, technology, vendors, and staff procedures support one another, the work becomes more manageable and the practice is better prepared when questions arise. 
          Need help making the technology side of HIPAA easier to manage? Let’s talk. 
          An SRA documents where ePHI exists, the threats and vulnerabilities that affect it, and the level of risk. The current rule does not prescribe one fixed schedule. Review frequency should reflect the practice’s environment, with updates when significant changes or incidents affect ePHI. 
          Generally, yes, when the provider creates, receives, maintains, or transmits PHI while performing services for the practice. The answer depends on the actual service relationship and access to PHI. 
          Yes. Diagnostic images maintained as part of a patient’s record can be PHI. When stored or transmitted electronically, they are subject to the Security Rule’s protections for ePHI. 
          Common gaps include incomplete risk analysis, outdated access lists, missing vendor documentation, weak account protection, untested recovery plans, and policies that no longer match how the practice actually works. 
          The Notice of Privacy Practices change tied to 42 CFR Part 2 took effect on February 16, 2026. The proposed Security Rule overhaul remains pending as of August 2026, and July 2027 is only the current anticipated date for final action. 
          Outcomes depend on the facts and may include technical assistance, corrective action, monitoring, a settlement, or a civil monetary penalty. Clear documentation and timely remediation help a practice explain what happened and how it responded. 
          Yes. Monitoring can help identify failed backups, suspicious logins, disabled security tools, unauthorized changes, and other technical issues. It supports compliance when alerts are reviewed, documented, and connected to a response process. 

          HIPAA Compliance Isn’t a Checkbox. Here’s What Omaha Healthcare Practices Actually Need to Do.  Read More »

          Security Awareness Training That Actually Works (Without Being Annoying) 

          It’s the third Tuesday of the quarter, and an email lands in every inbox with the subject line, “Mandatory Security Training – Complete by Friday.” You can practically hear the collective groan roll through the office. 
          Everyone clicks through the slides, guesses their way through the quiz, and moves on with the day. Then a convincing invoice request arrives two months later, and the employee facing it has never practiced what to do in that moment. 
          If that sounds familiar, you have not failed at cybersecurity. You may simply be relying on a training model designed to document completion instead of build better habits. For businesses in Omaha, Lincoln, and Council Bluffs, the goal is not to make employees cybersecurity experts. It is to help them recognize suspicious activity, slow down, and report it quickly. 
          A long annual presentation may satisfy an administrative requirement, but it gives employees very little practice. The Federal Trade Commission recommends reinforcing security messages with periodic refreshers and updates, rather than treating training as a one-time event. 
          Most employees are moving quickly, switching between tasks, answering customers, approving invoices, and trying to keep work on schedule. A realistic phishing message is designed to take advantage of that pace. 
          The 2026 Verizon Data Breach Investigations Report found that the non-intentional human element was present in 62% of breaches. That does not mean people are the only security problem. It does mean employee decisions remain an important part of the risk picture, alongside technical weaknesses and criminal tactics. 
          A large 2026 benchmark from KnowBe4 shows what repeated practice can change. The report analyzed 42 million simulated phishing tests across 14.8 million users at 64,000 organizations. Its average Phish-prone Percentage was 33.2% before training, 20.1% after 90 days, and 4.2% after one year of ongoing training and testing. These are vendor customer benchmarks, so every organization will not see identical results, but the direction is clear: consistent practice is more useful than a once-a-year reminderView the 2026 benchmark source. 
          Security awareness is not a course employees finish once. It is a set of habits the organization reinforces, and leadership sets the tone. 
          • Leadership participates. Owners and managers complete the same training and follow the same verification steps as everyone else. 
          • Reporting is treated as a win. Thank employees who flag suspicious messages, even when the message turns out to be legitimate. 
          • High-risk requests get a second check. Wire transfers, payroll changes, gift card requests, and unusual account updates should be verified through a known phone number or established process, not by replying to the message. 
          • Security habits stay visible. Password manager use, careful review of multi-factor authentication prompts, safe handling of personal devices, and quick reporting should appear in regular reminders and team conversations. 
          Done well, this stops feeling like another training assignment. It becomes part of how the team works. 
          A completion percentage tells you who opened the training. It does not tell you whether employees are becoming faster or more confident at recognizing risk. 
          • Phishing engagement rate. How many employees clicked, opened an attachment, entered information, or otherwise interacted with a simulation? 
          • Reporting rate. How many employees used the reporting process, and how quickly did they report? 
          • Repeat behavior. Are the same people making the same mistake, or are they improving after coaching? 
          • Simulation difficulty. Was the test easy, moderate, or difficult for the intended audience? Use that context before comparing one campaign with another. 
          The goal is not a perfect score. The goal is steady improvement and faster reporting when something looks wrong. 
          Security awareness training is just one piece of a comprehensive cybersecurity strategy. The most effective organizations take a layered approach that combines people, processes, and technology to reduce risk and improve resilience. 
          A trusted managed IT partner should help implement and maintain the technical safeguards that support your business, including: 
          • Identity and access management  
          • Endpoint protection  
          • Email security  
          • Regular patching   
          • Secure backups  
          • Continuous monitoring  
          • Vulnerability management  
          • Incident response plan.  
          Together, these layers help prevent attacks, limit their impact, and support a faster recovery when incidents occur. 
          Technology alone isn’t enough, and neither is training alone. Lasting cybersecurity comes from combining informed employees with well-designed systems, thoughtful policies, and ongoing guidance that evolves alongside today’s threats. The result is a security program that protects your business without getting in the way of the people who keep it running. 
          There is no universal schedule for every business. A practical starting point is short monthly refreshers paired with regular simulated phishing tests, then adjust the cadence based on employee roles, risk, and results. The important part is consistent reinforcement, not one long annual session. 
          It can, when it is part of an ongoing program. In KnowBe4’s 2026 customer benchmark, the average Phish-prone Percentage moved from 33.2% before training to 20.1% after 90 days and 4.2% after one year of training and testing. Those results are not a guarantee for every organization, but they support the value of repeated practice and measurement. See the source data. 
          Provide quick, private, judgment-free coaching. Explain the clues in the message, show the correct reporting process, and give the employee a chance to practice again. Public callouts can make people less willing to report a real mistake. 
          Results vary, but the KnowBe4 benchmark showed a measurable change within the first 90 days and a much lower average engagement rate after one year. Track your own baseline and trend instead of assuming a published benchmark will match your organization exactly. 
          Requirements vary by industry, framework, contract, and insurance policy. A slide deck may document that training occurred, but it may not satisfy requirements for recurring education, testing, reporting, or proof of completion. Confirm the exact requirements that apply to your business with the appropriate compliance, legal, or insurance resource. 
          Include password and multi-factor authentication habits, payment and payroll verification, safe use of personal devices, handling of sensitive information, physical security, and how to respond to suspicious texts, phone calls, collaboration messages, or AI-generated impersonation attempts. 
          No. Training reduces avoidable mistakes, but it does not replace technical protections. The strongest approach combines employee awareness with multi-factor authentication, secure email controls, monitored backups, patching, endpoint protection, and proactive network monitoring. 

          Security Awareness Training That Actually Works (Without Being Annoying)  Read More »

          Upgrade your Tax Game with InfiNet

          Tax season might steal the spotlight, but IT services are the unsung heroes that keep accountants running smoothly all year round. From cyber threats to system glitches, tech problems can be a headache—but with the right IT support, you can focus on what you do best without the stress. Here’s how InfiNet Solutions can help accountants not just survive tax season, but thrive long-term.

          System Updates: Stay Secure and Efficient

          With InfiNet Solutions, your systems are always up-to-date with the latest security patches and software enhancements. No more worrying about outdated systems or gaps in security—just smooth, efficient operations all year long.

          Thinking about moving to the cloud? InfiNet Solutions make it seamless. They’ll help you migrate your data safely and securely, ensuring it’s accessible from anywhere, at any time—so you can work smarter, not harder. This means no more scrambling for paper files or being tied to the office. You can access financial data, client records, and tax documents on-the-go, anytime, anywhere.

          InfiNet’s Cybersecurity solutions—like firewalls, encryption, and multi-factor authentication—keep your sensitive data safe from cyber threats. With us, you can rest easy knowing your client information is protected. This ensures client trust is maintained, and the risks of cyber-attacks don’t jeopardize your reputation or your practice’s financial security.

          Automation is the key to working smarter. InfiNet Solutions helps streamline your workflows, saving you time and reducing the chance for errors. This means you can spend more time on strategic tasks (and maybe even enjoy a coffee break!).

          24/7 Monitoring: Never Worry About Downtime

          With InfiNet’s 24/7 Monitoring, their systems are always being kept an eye on. They’ll catch issues before they become problems, so you can keep working without interruptions, day or night.

          Ready to Level Up Your Accounting Game? Contact InfiNet Solutions Today!

          Upgrade your Tax Game with InfiNet Read More »

          Cybersecurity Resolution: Start the Year with Stronger Passwords and Multi-Factor Authentication

          Why Strong Passwords Matter

          Weak or reused passwords remain one of the top vulnerabilities exploited by cybercriminals. According to Verizon’s 2024 Data Breach Investigations Report [https://www.verizon.com/business/resources/reports/dbir/], 81% of hacking-related breaches involved stolen or weak passwords. This staggering statistic underscores the importance of creating unique and complex passwords for all accounts.

          Tips for Creating Strong Passwords:

          Use a combination of uppercase and lowercase letters, numbers, and special characters.

          Avoid using easily guessable information like birthdays, names, or common words.

          Opt for passphrases—a series of random words strung together—to create memorable yet strong passwords.

          Use a password manager to generate and securely store your passwords.

          The Power of Multi-Factor Authentication

          Multi-factor authentication adds an essential layer of security by requiring users to verify their identity through at least two methods—something they know (password), something they have (a smartphone or hardware token), or something they are (fingerprint or facial recognition). MFA significantly reduces the risk of unauthorized access even if a password is compromised.

          How MFA Works:

          Login Attempt: Enter your username and password as usual.

          Second Verification: Approve a push notification, enter a code sent to your phone, or use a physical security key.

          Access Granted: After successful verification, access is granted to your account.

          According to Microsoft, enabling MFA blocks 99.9% of account compromise attacks [https://www.microsoft.com/en-us/security/business/zero-trust]. In today’s threat landscape, it’s no longer optional—it’s essential.

          Audit Your Current Passwords:

          Use tools like Have I Been Pwned [https://haveibeenpwned.com/] to check if any of your passwords have been leaked.
          Update all compromised or weak passwords immediately.

          Adopt a Password Manager:

          Tools like LastPass, Dashlane, 1Password, or Passportal can help you generate and manage strong passwords effortlessly.

          Enable MFA Across All Accounts:

          Start with critical accounts such as email, banking, and workplace systems.

          Check with InfiNet Solutions team to ensure MFA is enforced organization wide.

          Educate Your Team:

          Conduct training sessions with InfiNet to teach employees about the importance of strong passwords and MFA.

          Looking Ahead

          Making cybersecurity a priority in 2025 isn’t just a smart business decision—it’s a necessary one. With cyberattacks becoming more sophisticated, taking proactive steps now can save you from costly breaches and downtime later. Starting with stronger passwords and multi-factor authentication is a simple yet impactful way to protect your business and personal information.

          Together, let’s make 2025 your most secure year yet. Contact us today!

          Cybersecurity Resolution: Start the Year with Stronger Passwords and Multi-Factor Authentication Read More »

          Talk to our Team