Author: rory-admin

  • Microsoft is retiring voice and SMS verification in favor of passkeys for Entra users starting February 2027, we tell you how to set this up NOW before you lose access

    Microsoft is retiring voice and SMS verification in favor of passkeys for Entra users starting February 2027, we tell you how to set this up NOW before you lose access

    If your business still has Microsoft 365 users receiving text messages or phone calls to verify their identities, Microsoft has officially put an expiration date on that workflow. Beginning February 1, 2027, Microsoft will retire the SMS and voice authentication services it currently provides through Microsoft Entra ID, and organizations that have not prepared could see users run directly into sign-in disruptions.

    This is not another security recommendation that businesses can indefinitely postpone because the old method still works. Microsoft is actively moving Entra customers toward phishing-resistant authentication such as passkeys, Windows Hello for Business, and FIDO2 security keys, and the transition starts well before February 2027.

    So, what exactly is Microsoft changing? Starting September 1, 2026, Microsoft will make passkeys the default authentication experience for users who are currently enabled for SMS or voice authentication. Those users will automatically become eligible for passkeys and Microsoft can begin prompting them to register one when they complete MFA.

    Then the bigger change arrives on February 1, 2027. Microsoft-provided SMS messages and voice calls will no longer be available as native Entra ID authentication services, and there is no permanent opt-out from that change.

    For businesses, the important dates and consequences are:

    • September 1, 2026: Microsoft begins automatically enabling passkeys for users who are enabled for SMS or voice authentication and can prompt those users to register. Organizations can prepare before this process starts rather than introducing a new authentication workflow to employees without planning or communication.
    • February 1, 2027: Microsoft-provided SMS and voice authentication are retired. Users whose only MFA option is SMS or voice can encounter a blocking registration experience and will have to establish a passkey before they can continue signing in normally.
    • After February 1, 2027: Organizations that genuinely need SMS or voice authentication will need to use a supported customer-managed telecommunications provider instead of Microsoft’s native delivery service. Microsoft recommends moving users to phishing-resistant authentication wherever possible rather than treating third-party telephony as the default replacement.

    That last point matters because this is not simply Microsoft swapping one MFA delivery vendor for another. The strategic direction is clear: Microsoft wants organizations to stop relying on codes that can be intercepted, relayed, socially engineered, or stolen through phishing.

    Why are they making this change now? SMS MFA was a major improvement over passwords alone, and businesses were right to adopt it when stronger MFA options were less accessible. The problem is that cybercriminals have become very good at attacking authentication workflows instead of trying to break the underlying cryptography. A six-digit verification code is still a secret that a human can be convinced to type into the wrong website. Attackers can build convincing Microsoft 365 login pages, proxy authentication sessions in real time, steal credentials, collect the MFA code the victim enters, and potentially capture authenticated sessions.

    Telephone-based authentication introduces additional risks such as SIM swapping and telecommunications account compromise. Microsoft specifically describes passwords, SMS codes, and email one-time codes as phishable credentials and is positioning passkeys as a replacement built around phishing-resistant public-key cryptography. A passkey works differently because there is no reusable verification code for an employee to accidentally hand to an attacker. The credential is cryptographically tied to the legitimate service, which makes the familiar fake-login-page attack substantially harder to execute successfully.

    You may be wondering what a passkey is, passkey is a FIDO2-based authentication credential that uses public-key cryptography rather than a shared password or temporary code. The private portion of the credential remains with the user’s device or credential provider, while Microsoft Entra receives what it needs to verify that the legitimate credential is present.

    Microsoft Entra currently supports both synced and device-bound passkeys. Synced passkeys can live in supported credential managers and follow a user across compatible devices, while device-bound passkeys can be stored in Microsoft Authenticator, Windows, or a physical FIDO2 security key. Businesses therefore do not have to choose one universal piece of hardware for every employee. The appropriate approach can vary by role, device ownership, administrative privilege, regulatory requirements, and how the organization manages endpoints.

    The good news is you can start now, there is no reason to wait until January 2027 to deal with this. Microsoft already supports passkeys in Entra ID, including Entra ID Free, and organizations can begin enabling them, registering users, testing applications, and building recovery procedures today.

    Starting early also gives your IT provider a chance to find the exceptions before they become emergencies. An employee with an unusual mobile device, an executive traveling internationally, an administrator with elevated privileges, or a legacy business process that depends on telephone authentication is much easier to deal with months before a mandatory cutoff.

    Step 1: Find out who is still using SMS or voice

    Before changing authentication policies, determine which Entra users are actually dependent on SMS or voice. Microsoft recommends identifying these users first so that organizations can target their migration rather than blindly changing authentication settings tenant-wide.

    This assessment should also distinguish between users who merely have a phone number registered and users who genuinely depend on phone authentication. Someone who already uses Windows Hello or a FIDO2 credential may require little intervention, while an employee whose only usable second factor is a text message needs attention.

    Step 2: Enable passkeys in Microsoft Entra

    Administrators can configure passkeys under the Authentication Methods policies in the Microsoft Entra admin center. Microsoft’s current deployment model uses passkey profiles, which allow administrators to define permitted passkey types, restrictions, attestation requirements, and the groups that should receive the policy.

    A controlled pilot is usually preferable to immediately targeting every employee. Start with IT personnel and a small group of cooperative users, confirm the registration and sign-in experience on the devices your organization actually uses, and then expand the deployment.

    Step 3: Have users register their passkeys

    Users can register passkeys through Microsoft’s Security Info experience once their organization has enabled the appropriate authentication method. Depending on the organization’s configuration, that passkey can be stored in Microsoft Authenticator, on a Windows device, in a supported synced credential provider, or on a physical FIDO2 security key.

    For Microsoft Authenticator, Microsoft supports passkey registration on current iOS and Android versions and recommends registering directly through the Authenticator application when that deployment model is being used. Organizations should test the exact workflow they intend to give employees before distributing instructions company-wide.

    Step 4: Plan for account recovery before you enforce anything

    Stronger authentication does not eliminate the need for recovery procedures. Employees replace phones, laptops fail, security keys disappear, and administrators eventually have to help someone who no longer possesses the credential they normally use.

    Microsoft Entra supports Temporary Access Pass, or TAP, specifically to help users bootstrap passwordless authentication methods or recover when a strong authentication method is unavailable. A TAP can be time limited and configured for controlled onboarding or recovery scenarios.

    Your IT team should understand this process before passkeys become mandatory. Locking down authentication without establishing a recovery workflow is an excellent way to turn a security improvement into an avoidable Monday-morning support emergency.

    Step 5: Protect administrators more aggressively than ordinary users

    Administrative accounts deserve stronger requirements because compromise of an administrator can affect the entire Microsoft 365 environment. Global Administrators and other privileged roles should ideally have more than one phishing-resistant credential available so that the loss of a single phone, laptop, or security key does not create an administrative lockout. For privileged users, physical FIDO2 security keys are still worth serious consideration. Microsoft specifically identifies them as a strong option for elevated users and regulated environments because the private credential remains on the physical authenticator.

    So, what should your business be doing now? February 2027 may sound comfortably far away, but authentication changes are much easier to deploy gradually than during a deadline-driven migration. Businesses should use the remaining time to turn passkeys into an ordinary part of their Microsoft 365 environment rather than something employees first encounter when their old MFA method stops working.

    A sensible preparation plan includes:

    • Audit your current authentication methods now. Identify employees who still depend on SMS or voice and pay particular attention to executives, administrators, remote employees, and users with unusual device requirements.
    • Enable passkeys and run a pilot deployment. Test Microsoft Authenticator, Windows-based passkeys, synced passkeys, and FIDO2 security keys where appropriate rather than assuming one method is ideal for every employee.
    • Establish a recovery process. Document how your IT team will use methods such as Temporary Access Pass when an employee loses a registered device or needs to enroll a replacement credential.
    • Communicate with employees before changing their sign-in experience. A short explanation of why passkeys are being introduced can prevent confusion and reduce help desk calls when registration prompts begin appearing.
    • Review Conditional Access at the same time. Moving to phishing-resistant credentials creates an opportunity to strengthen access requirements for administrators, remote access, sensitive applications, and other higher-risk scenarios.
    • Do not wait until January 2027. You want February 1 to be an uneventful date on the calendar because your employees migrated months earlier, not the day your organization discovers which users were still relying entirely on text messages.

    Can you keep using SMS? Technically, yes, but Microsoft will no longer provide the underlying SMS or voice delivery service after February 1, 2027. Organizations with a documented business, regulatory, or operational requirement will be able to select a supported telecommunications provider through Microsoft’s Security Store and route authentication through that provider.

    Microsoft says provider information will become available beginning September 18, 2026, with customer configuration scheduled to become available beginning October 30, 2026. For most small and midsize businesses, however, moving users to passkeys is likely to be both simpler and more aligned with Microsoft’s long-term authentication strategy. You should not wait until February 2027 to move on this. Microsoft’s retirement of native SMS and voice authentication is another signal that traditional MFA is evolving. Having MFA enabled is no longer the finish line because organizations now have to consider whether the authentication method itself can withstand modern phishing, session theft, social engineering, and identity attacks.

    The businesses that start preparing now have plenty of time to audit their users, deploy passkeys, test recovery procedures, and address exceptions without disrupting employees. The businesses that ignore the change until early 2027 may instead discover their authentication dependencies when Microsoft starts blocking the workflow they have relied on for years.

    Valley Techlogic can help your organization review its Microsoft 365 and Entra authentication environment, identify users who still depend on SMS or voice verification, deploy passkeys, strengthen Conditional Access policies, and create a practical recovery process before the February 2027 deadline. The goal is not simply to satisfy another Microsoft platform change, but to leave your organization with an authentication system that is substantially harder for attackers to defeat. Learn more today with a consultation.

    This article was powered by Valley Techlogic, leading provider of trouble free IT services for businesses in California including Merced, Fresno, Stockton & More. You can find more information at https://www.valleytechlogic.com/ or on Facebook at https://www.facebook.com/valleytechlogic/ . Follow us on X at https://x.com/valleytechlogic

  • Worried about “shadow IT” in your business?

    Worried about “shadow IT” in your business?

    Shadow IT used to mean an employee installing Dropbox, signing up for a project management platform, or using an unapproved messaging app without telling IT. Generative AI has made the problem much bigger. Today, an employee can open a browser, create an account with an AI service, paste in company information, and start using it for research, writing, analysis, customer support, coding, or decision-making within minutes.

    They may genuinely be trying to work faster. But without proper oversight, those tools can create security risks, produce unreliable answers, and sometimes make employees less productive instead of more productive. For businesses adopting AI, the question is no longer simply whether employees are using it. The question is whether you know which AI tools they are using, what information they are giving those tools, and whether the answers coming back can actually be trusted.

    Traditional shadow IT usually required someone to download software or connect a new service to a company system, AI often requires nothing more than a website. Employees can access dozens of AI assistants, writing tools, meeting transcription services, browser extensions, coding assistants, document analyzers, and automated research platforms without involving management or IT.

    That creates two major problems:

    • The business may have no visibility into where its data is going. Employees might paste contracts, financial information, customer records, source code, internal emails, meeting notes, or strategic plans into services that have never been reviewed.
    • Employees may trust AI-generated answers more than they should. An answer that sounds polished and authoritative can still be incomplete, outdated, misleading, or completely wrong.

    Neither problem necessarily comes from malicious employees. In most cases, employees are simply trying to get their jobs done. That is exactly why businesses need a strategy for AI rather than pretending employees will not use it. Consider how people actually use AI, someone receives a long customer email and asks an AI assistant to summarize it or someone uploads a spreadsheet because they want help understanding the numbers.

    A salesperson pastes notes from a confidential meeting into an AI tool and asks it to draft a proposal. A developer submits proprietary source code to an AI assistant to troubleshoot an error. An employee uploads a contract and asks, “What should I be worried about?” Each action may seem harmless in isolation, collectively, however, they can expose some of the most sensitive information your company possesses.

    Depending on the service, account type, configuration, and contractual terms, submitted information may be retained, logged, processed by additional systems, or handled in ways that do not satisfy your organization’s privacy, compliance, or contractual requirements. Even if the provider itself has strong security practices, your company still needs to know what information employees are authorized to disclose to it. A secure AI platform cannot protect your business from an employee sharing information they were never supposed to provide in the first place.

    Bad AI answers can also be a productivity killer. Security gets most of the attention around shadow AI, but bad answers can be just as costly. AI is remarkably good at generating plausible responses. Unfortunately, plausible and correct are not the same thing. An employee might spend fifteen minutes asking an AI assistant how to solve a problem, receive a confident answer, follow the instructions, discover they do not work, and then spend another hour troubleshooting the problems created by the original advice.

    They’re not saving any time by troubleshooting the problem with AI, they’re creating an extremely sophisticated way to waste an afternoon. The problem becomes more serious when AI-generated information makes its way into customer communications, financial decisions, technical configurations, legal documents, or management reports.

    Two risks deserve particular attention:

    • AI can confidently invent information. Fabricated statistics, nonexistent software settings, incorrect regulations, made-up citations, and inaccurate technical instructions can all look legitimate.
    • Employees can lose time validating low-quality output. If every answer requires extensive fact-checking, correcting, and rewriting, the organization may actually be adding another step to the workflow rather than removing one.

    The goal of AI adoption should be measurable productivity improvement, not simply maximizing how often employees interact with AI. This is where many businesses make a mistake, they either allow everything or ban everything. Neither approach works particularly well, a blanket ban often pushes AI usage underground. Employees who believe a tool makes them dramatically more productive may simply use it without telling anyone. Unlimited access creates the opposite problem. Employees can experiment with services that have never been evaluated for security, privacy, reliability, or business suitability. A better strategy is managed adoption.

    Your organization can approve specific AI platforms, define which types of data can be used with them, configure business-grade security controls where available, and train employees on appropriate use. Employees get useful tools, management gets visibility and IT gets the ability to put guardrails around everything.

    You cannot manage technology you do not know exists. An effective shadow IT review should therefore combine technical discovery with conversations about how employees actually work.

    1. Inventory the Applications Employees Are Using

    Start by identifying the software and online services being accessed across the organization. Review endpoint software inventories, browser extensions, SaaS applications, identity provider sign-ins, expense reports, corporate card transactions, and recurring subscriptions. Pay particular attention to AI assistants, transcription platforms, document-processing tools, browser-based productivity applications, and services employees may have purchased individually. The goal is not immediately to block everything unfamiliar but to create visibility into how and when tools are being used.

    2. Ask Employees How They Are Using AI

    Technical tools will not reveal everything, you’ll need to actually talk to your employees. Ask which AI platforms they use, what tasks they use them for, what information they typically provide, and which tools genuinely save them time. You may discover highly effective workflows worth formally adopting, you may also discover someone casually uploading confidential customer documents into a consumer AI service. An audit should find both.

    3. Classify Your Business Information

    Employees cannot follow data-handling rules that have never been defined. Create understandable categories for information such as public, internal, confidential, and highly restricted. Then define what employees may provide to external AI systems. A marketing employee asking an AI assistant to brainstorm headlines using information already published on your website is very different from an employee uploading payroll records, your policy should make that distinction obvious.

    4. Approve a Small Set of Business AI Platforms

    Give employees a sanctioned alternative, select AI platforms that meet your organization’s security, privacy, identity, and administrative requirements. Where possible, use business or enterprise accounts rather than unmanaged personal accounts. Centralized platforms can also make it easier to implement authentication requirements, access controls, auditing, data protections, and employee offboarding. If the approved platform is useful and easy to access, employees have much less reason to create their own solution.

    5. Establish an AI Acceptable Use Policy and Review It Regularly

    AI governance should not be a document that gets written once and forgotten. Define what employees can use AI for, which services are approved, what information cannot be submitted, when AI-generated information must be verified, and who employees should contact before adopting a new tool. Then revisit the policy as your business and the technology change. AI products are evolving too quickly for a policy written today to remain untouched for the next five years.

    The Goal Is Not to Stop Employees From Using AI

    Generative AI can absolutely improve productivity. It can help employees summarize information, draft documents, analyze data, troubleshoot problems, automate repetitive tasks, research unfamiliar subjects, and get through routine administrative work faster, but AI works best when it is treated as a business tool rather than a free website everyone can use however they want. Businesses already manage email, cloud storage, endpoint security, financial systems, and customer databases, AI deserves the same attention.

    The organizations that benefit most from AI will probably not be the ones that give employees unrestricted access to every new tool, they will be the ones that figure out where AI genuinely improves the work, provide employees with secure ways to use it, and establish clear boundaries around the information that should never leave the business. Shadow IT thrives when employees have a problem and IT has not provided an approved solution.

    Find those problems first, give employees better options, and AI can become a productivity tool instead of another source of risk. Valley Techlogic is already helping clients navigate their AI strategies and stamp out unnecessary risks found when employees are left to their own devices in finding AI solutions that assist with their workload. We can help you develop a plan that will both increase productivity while keeping data security in mind, and can recommend tools that are industry tested and proven. Learn more today with a consultation.

    This article was powered by Valley Techlogic, leading provider of trouble free IT services for businesses in California including Merced, Fresno, Stockton & More. You can find more information at https://www.valleytechlogic.com/ or on Facebook at https://www.facebook.com/valleytechlogic/ . Follow us on X at https://x.com/valleytechlogic

  • This week Anthropic announced it will “watermark” text, including code, and the internet is having a meltdown over it

    This week Anthropic announced it will “watermark” text, including code, and the internet is having a meltdown over it

    Anthropic dropped a surprisingly consequential announcement this week: text generated by supported Claude models will contain an invisible, machine-readable watermark. Not just images, not just obvious AI-generated media, now text itself will be easily identifiable as AI generated. Also, importantly for developers, that even includes text generated through products such as Claude Code.

    Predictably, portions of the internet reacted as though Anthropic had announced that every Claude response would arrive with a scarlet letter attached to it. The reality is more complicated, Anthropic is not doing this simply because it woke up one morning and decided people should be able to identify Claude-written emails, blog posts and Python functions. The change is closely tied to the European Union’s AI Act, specifically the transparency requirements that became applicable on August 2, 2026. Those rules require providers of generative AI systems to make artificially generated or manipulated content detectable in a machine-readable form.

    Anthropic has signed the EU AI Act’s Article 50 Code of Practice on Transparency of AI-Generated Content and is implementing the marking system as part of that commitment.  In other words, this is as much a regulatory story as it is a technology story. So, what is Anthropic actually doing? Anthropic says supported Claude models will use two different mechanisms.

    Generated text will contain an “imperceptible watermark” embedded directly into the text itself. Generated files such as PNG, JPG and SVG files can additionally carry signed provenance metadata using C2PA, the Coalition for Content Provenance and Authenticity standard.

    The text watermark is the interesting part. Anthropic says it is part of the generated text itself, which means the identifying signal can survive copying and pasting and may survive some subsequent editing. It is also implemented at the model level rather than being something added only by the Claude website.

    That means supported models can produce marked output regardless of whether you are accessing them through Claude, the Anthropic API, Claude Code, Claude Cowork, Claude Tag, AWS, Google Cloud or Microsoft Foundry. Anthropic says the system will apply worldwide, not just to customers located inside the European Union.  The EU passed the rule, but users everywhere get the implementation.

    Anthropic’s current rollout policy is that Claude models launched in the EU on or after August 2, 2026 support machine-readable marking from launch. Models released before August 2 are covered by a transition period, and Anthropic says it is working to add marking support to those older versions as well.

    So, if your response to this news is, “I’ll just keep using an older Claude model,” enjoy that workaround while it lasts and yes, this new rule will apply to code. This is actually where the discussion gets considerably more interesting. Claude Code is explicitly included among the products covered by Anthropic’s marking system, and Anthropic says embedded watermarks apply to generated text from supported models. Code, conveniently enough, is also text.

    That raises questions that are very different from the familiar debate about students submitting AI-generated essays or people publishing machine-written LinkedIn thought leadership about how drinking coffee taught them seven lessons about enterprise leadership.

    Increasingly, developers for example use AI as part of normal software development. Claude might generate an entire function. It might refactor an existing function. It might replace five lines. It might fix a bug. It might add comments. It might translate PowerShell into Python. It might simply suggest a more efficient conditional statement. At what point does Claude-generated code become Claude-processed code?

    Anthropic itself acknowledges exactly this problem with text generally. A detected watermark does not prove that Claude originally authored the material. Someone may have written something themselves and then asked Claude to proofread, translate, summarize or transform it.

    The resulting output can still carry a Claude watermark. There may not be a distinction between “Claude processed this” and “Claude wrote this”. Some of the objections are predictable from those who already, or aspired, to use AI ubiquitously in their creative process with limited input beyond prompting. Other concerns are simply related to using AI as an assistant with limited input into the creative process (such as grammatical corrections or checking for bugs).

    The controversy largely falls into a few categories:

    • Authorship. If someone writes a document and uses Claude for editing, the resulting text may still contain the watermark. A detector therefore cannot automatically establish who actually wrote the underlying material.
    • Code ownership and copyright. Developers are asking how machine-readable evidence of AI involvement might someday interact with software copyright disputes, licensing, corporate intellectual property policies and provenance requirements.
    • Privacy. Some critics dislike the idea that text can carry an invisible indication of having passed through a particular company’s system.
    • Detection asymmetry. Anthropic has not yet published complete technical details about the text watermark. The company says it plans to provide detection mechanisms for users and third parties, including a free API for checking Claude watermarks.

    That last point has produced a particularly intense reaction. People are understandably uncomfortable with the idea of a vendor invisibly marking their output while being the only party initially capable of reliably identifying that mark. Anthropic appears to recognize the problem. Its documentation says it intends to enable users and third parties to detect the markings themselves and will publish additional technical documentation.

    Until that documentation exists, though, there are unanswered technical questions. We do not yet know enough about the implementation to confidently say how resistant the text watermark will be to reformatting, linting, refactoring, partial rewriting, token substitution or other transformations. We do know that the implementation involves pattern matching.

    When a human writes it’s naturally random, when AI writes it’s much more predictable. It’s this predictability that will be used as a “watermark”. Where you may not consciously notice for example, that every 5th sentence starts with a word that begins with a capital “T”, AI can. It’s in the pattern matching component that will form digital watermark will form.

    Implementation is probably the most important part of the announcement, and one that will inevitably disappear as AI detection products begin adding giant green and red “CLAUDE DETECTED” buttons to their interfaces. Anthropic explicitly warns that its marking system is not conclusive proof of authorship. A positive detection means the content may have been processed by Claude. It does not necessarily mean Claude created the underlying ideas, original language or data. Likewise, failing to detect a watermark does not prove that something was written by a human.

    Anthropic lists several reasons a mark might disappear or become undetectable. Text can be heavily edited, paraphrased, translated or mixed with other writing. Very short passages may not contain enough information for a reliable signal. File metadata can disappear during format conversion, screenshots or re-saving.  That makes this fundamentally different from a cryptographic certificate saying, “Claude wrote this exact document.”

    We are rapidly approaching a world in which enormous amounts of text, software, imagery, music and video are machine generated or machine assisted. Knowing something about where that material came from has value. It could help content platforms distinguish synthetic media. It could give researchers better information about training datasets. It could make certain types of fraud easier to investigate. It could improve provenance tracking inside enterprises that increasingly have humans and AI systems collaboratively producing documents and software.

    There is even a longer-term AI problem here. As synthetic content floods the internet, future models risk consuming increasing quantities of previous models’ output during training. Reliable provenance systems could theoretically help developers identify and filter some of that synthetic data. Several technologists have pointed to exactly this potential benefit amid the backlash. The problem is not necessarily that provenance exists, the problem is what people eventually decide provenance means.

    There is a danger in bad interpretation, however. We already spent several years watching unreliable “AI detectors” accuse students of cheating because their sentence structure looked statistically suspicious. A genuine provider-generated watermark is much stronger evidence that an AI system touched something, but even Anthropic is explicitly saying that this does not establish authorship.  That nuance needs to survive contact with HR departments, universities, automated compliance platforms and procurement policies.

    Anthropic will almost certainly not be the last major AI company dealing with this problem. The European Commission says Article 50’s transparency obligations apply from August 2, 2026, and the Code of Practice specifically calls for AI-generated audio, images, video and text to be marked in machine-readable formats using techniques that are effective, interoperable, robust and reliable where technically feasible.

    Anthropic is therefore an early and very visible example of a broader shift. The internet spent the first few years of the generative AI boom arguing about whether AI-generated content could be detected. We are now entering the next phase, where regulators are increasingly asking whether AI companies should deliberately make it detectable, those are very different questions.

    For developers, writers, businesses and anyone else who routinely uses LLMs as part of their workflow, the most important consequence may not be that Claude is watermarking its output. It may be that AI provenance is about to become a normal part of the creation process. Whether that turns into a genuinely useful transparency mechanism or the world’s largest automated “gotcha” system will depend considerably less on the watermark itself than on what everyone else decides to do with it.

    Digital watermark or not, AI is here to stay and we’ve seen our clients implement AI solutions directly into their business with Valley Techlogic’s guidance. How you implement AI is just as important as how you will use it day to day, and questions surrounding data security and privacy, access controls, retention, compliance, and governance should be answered before these tools become embedded in your organization’s workflows. If you would like to learn more about AI readiness and how Valley Techlogic can help your business with its AI strategy, schedule a free consultation today to get started.

    This article was powered by Valley Techlogic, leading provider of trouble free IT services for businesses in California including Merced, Fresno, Stockton & More. You can find more information at https://www.valleytechlogic.com/ or on Facebook at https://www.facebook.com/valleytechlogic/ . Follow us on X at https://x.com/valleytechlogic

  • Can Password Managers Be Hacked? Our 3 Best Password Manager Recommendations

    Can Password Managers Be Hacked? Our 3 Best Password Manager Recommendations

    Password managers have become one of the most important cybersecurity tools available to individuals and businesses. They make it practical to create a unique, complex password for every account without having to memorize hundreds of credentials.

    But because a password manager stores so much sensitive information, it is reasonable to ask an important question:

    Can password managers be hacked? The honest answer is yes. Any software, device, or online service can potentially be attacked. However, that does not mean using a password manager is more dangerous than managing passwords yourself.

    For most people and businesses, the opposite is true. A reputable password manager dramatically reduces the risks created by weak passwords, password reuse, spreadsheets, browser notes, sticky notes, and credentials shared through email or text messages.

    How does a password manager protection your passwords? A properly designed password manager encrypts your vault before sending it to the provider’s servers. The provider should not possess the information needed to decrypt your stored passwords.

    This approach is often described as zero-knowledge encryption. Your vault can be synchronized between devices, but its contents remain encrypted until you unlock it with your master password or another approved authentication method.

    That does not make a password manager invincible. An attacker could still attempt to:

    • Steal your master password through phishing, malware, or social engineering
    • Access an already unlocked computer, phone, or browser session
    • Exploit a vulnerability in the password manager’s application or browser extension
    • Compromise the provider’s infrastructure and steal encrypted vault data
    • Trick an employee into approving a fraudulent multifactor authentication request

    The biggest practical risk is usually not someone breaking the encryption itself. It is an attacker stealing the user’s master password, compromising their device, or convincing them to approve access. Is it still safer to use a password manager?Yes, since people tend to reuse the same password across multiple websites or make minor variations that are easy for attackers to predict when they don’t use one. When one website is breached, criminals can test the stolen password against email, banking, Microsoft 365, social media, and other services.

    A password manager allows every account to have a long, random, and completely unique password. If one website is compromised, the stolen password cannot be reused to access your other accounts. Password managers also makes it easier to identify reused passwords, detect known compromised credentials, securely share business accounts, and revoke access when an employee leaves.

    The goal is not to eliminate every possible risk, there is no product that can promise that. The goal is to replace unsafe password habits with a system that is considerably harder to compromise.

    So, what are our password manager recommendations? Valley Techlogic recommends Bitwarden, 1Password, and Proton Pass. We feel it’s notable that of August 2026, none of these providers has publicly reported a breach that exposed customers’ decrypted password vaults. All three use strong encryption and have undergone independent security reviews. The best choice depends on your budget, technical requirements, privacy preferences, and the people who will be using it.

    1. Bitwarden

    Bitwarden is an established open-source password manager with options for individuals, families, and businesses. Its source code can be inspected publicly, and the company conducts recurring third-party security audits, source-code assessments, and penetration testing.

    Pros

    • Open-source applications and server components provide a high degree of transparency
    • Strong free plan and reasonably priced paid options
    • Available on major browsers, computers, and mobile devices
    • Supports business collections, secure credential sharing, and administrative controls
    • Can be self-hosted by organizations with the expertise to maintain it securely
    • Includes reports for weak, reused, and exposed passwords

    Cons

    • The interface is functional but may feel less polished than 1Password
    • Some administrative and reporting features require a paid business plan
    • Self-hosting adds significant maintenance and security responsibility
    • New or less technical users may need additional training during deployment

    Best for: Cost-conscious businesses, technical teams, open-source advocates, and organizations that want flexible deployment options.

    2. 1Password

    1Password is known for its polished interface and approachable user experience. In addition to your account password, it uses a locally generated Secret Key that strengthens the encryption of your vault. The company states that it has not experienced a breach of its password-management service. During the 2023 Okta support-system incident, 1Password detected suspicious activity involving its employee-facing Okta environment but reported that no user data or sensitive systems were compromised.

    Pros

    • Excellent interface that is easy for nontechnical users to understand
    • Secret Key provides additional protection beyond the account password
    • Strong family and business-sharing features
    • Useful administrative controls for onboarding and offboarding employees
    • Travel Mode can temporarily remove selected vaults from a device
    • Watchtower identifies compromised websites, vulnerable passwords, and other security concerns

    Cons

    • No permanent free plan for general password-manager use
    • Typically costs more than Bitwarden
    • The complete product is not open source
    • Users must protect both their account password and Emergency Kit containing the Secret Key

    Best for: Businesses that prioritize ease of use, employee adoption, polished administration, and a low-friction user experience.

    3. Proton Pass

    Proton Pass is part of Proton’s privacy-focused ecosystem, which also includes Proton Mail, Proton VPN, Proton Calendar, and Proton Drive. Proton Pass is open source, uses end-to-end encryption, and has undergone independent security testing by Cure53. Its audit covered the mobile applications, browser extensions, and API.

    Pros

    • Open-source applications with publicly available security information
    • Strong privacy focus and end-to-end encryption
    • Clean, modern interface
    • Integrates well with other Proton services
    • Supports email aliases that can reduce spam and limit account tracking
    • Competitive free and paid options

    Cons

    • Newer than Bitwarden and 1Password, with a shorter operational history
    • Business-management features may not be as mature as more established competitors
    • Organizations already standardized on another email or identity ecosystem may receive less benefit from Proton integration
    • Some advanced features require a paid Proton subscription

    Best for: Privacy-conscious individuals, Proton customers, small businesses, and users who value encrypted email aliases alongside password management.

    You may be wondering which of these three you should choose for your business. For many businesses, 1Password offers the smoothest user experience and may require the least training. Bitwarden is an excellent choice for businesses that want strong security, open-source transparency, and competitive pricing. Proton Pass is particularly attractive for privacy-focused users and organizations that already use, or plan to use, other Proton services.

    The most important factor is not choosing the theoretically perfect password manager. It is selecting a reputable product that your team will actually use consistently.

    So how can you use a password manager safely? A password manager should be part of a broader account-security strategy. Simply installing one is not enough. Use a long and unique master password that has never been used anywhere else. A memorable passphrase made from several unrelated words is generally easier to remember and more difficult to guess than a short, complicated password.

    Enable multifactor authentication on the password-manager account. Whenever possible, use a passkey, hardware security key, or authenticator application instead of SMS. Keep computers, phones, browsers, and password-manager applications updated. Avoid installing unnecessary browser extensions, and use reputable endpoint-security software to reduce the risk of credential-stealing malware.

    Businesses should also establish procedures for securely sharing credentials, removing former employees, reviewing administrative access, and recovering accounts when an authorized user loses access. Password managers can be attacked, just like email providers, banks, cloud platforms, and other online services. That is not a good reason to avoid them.

    A reputable password manager stores your credentials in an encrypted vault and makes it possible to use a different random password for every account. This protects you from one of the most common causes of account compromise: reused credentials.

    Bitwarden, 1Password, and Proton Pass are all strong options with different advantages. None can guarantee that an attack will never occur, but each offers a substantially safer approach than reused passwords, shared spreadsheets, browser notes, or credentials passed between employees through email.

    Valley Techlogic can help your organization select, configure, and deploy a password manager that fits your staff, security requirements, and budget. We can also help establish secure onboarding, offboarding, multifactor authentication, and credential-sharing procedures so the password manager becomes part of a complete security program rather than another unused application. Learn more today with a consultation.

    This article was powered by Valley Techlogic, leading provider of trouble free IT services for businesses in California including Merced, Fresno, Stockton & More. You can find more information at https://www.valleytechlogic.com/ or on Facebook at https://www.facebook.com/valleytechlogic/ . Follow us on X at https://x.com/valleytechlogic

  • DKIM? DMARC? How to stop scammers from using your company’s domain for nefarious purposes

    DKIM? DMARC? How to stop scammers from using your company’s domain for nefarious purposes

    You have probably heard the terms SPF, DKIM, and DMARC thrown around during conversations about email security. They sound technical, and it can be tempting to assume they are only relevant to large companies or IT departments.

    In reality, these protections matter to every business that uses email. Without them, scammers may be able to send fraudulent messages that appear to come from your company’s domain. They can impersonate executives, request payments, distribute malware, or trick customers into revealing sensitive information.

    Even if fraudulent email never touches your actual email system, your company’s name and reputation can still take the hit. Starting with DMARC, which stands for Domain-based Message Authentication, Reporting, and Conformance.

    DMARC works alongside two other email authentication technologies:

    • SPF, or Sender Policy Framework, identifies which servers are authorized to send email for your domain.
    • DKIM, or DomainKeys Identified Mail, adds a digital signature that helps prove an email was authorized and was not altered in transit.

    Together, these technologies give receiving email systems a way to determine whether a message claiming to be from your domain is legitimate.

    So how does domain spoofing work?Email was not originally designed with strong identity verification. In many cases, a scammer can place your company’s domain in the visible “From” field of an email without gaining access to your Microsoft 365, Google Workspace, or other email account.

    To the recipient, the message may appear to come from:

    The scammer might then request a wire transfer, send a fake invoice, ask an employee to purchase gift cards, or direct a customer to a fraudulent login page. This is known as domain spoofing. It is different from an attacker breaking into an actual mailbox, but it can still be extremely damaging.

    Next, SPF is a DNS record that lists the email services allowed to send messages on behalf of your domain.

    For example, if your company uses Microsoft 365, your SPF record should authorize Microsoft’s mail servers. If you also use a marketing platform, ticketing system, or invoicing application, those systems may need to be included as well. When a receiving mail server gets a message claiming to come from your domain, it can compare the sending server against your SPF record.

    A properly configured SPF record helps identify unauthorized senders. However, SPF alone is not enough. It can fail when messages are forwarded, and it does not always protect the address users see in the From field.

    Lastly, DKIM adds a cryptographic signature to outgoing email.

    The sending platform uses a private key to sign the message. The matching public key is published in your domain’s DNS records. Receiving systems can use that public key to verify that the message was authorized by your domain and that important parts of the email were not modified after it was sent.

    DKIM is especially important for cloud email platforms and third-party services that send email on your behalf.

    If your company uses services such as email marketing tools, billing platforms, customer relationship management systems, or help desk software, each service may require its own DKIM configuration. DMARC brings SPF and DKIM together and tells receiving email systems what to do when authentication fails.

    A DMARC policy can instruct the receiving system to:

    • Deliver suspicious messages to spam or quarantine
    • Reject unauthorized messages completely

    DMARC also provides reporting. These reports can show which systems are sending email using your domain and whether those messages are passing authentication. This visibility is extremely valuable. It can help uncover forgotten applications, configuration problems, and unauthorized attempts to impersonate your business.

    Many companies publish a DMARC record with a monitoring-only policy and never move beyond it. A monitoring policy is a good starting point, but it does not instruct receiving mail systems to block spoofed messages. It mainly collects information. Businesses are often hesitant to enforce DMARC because they are concerned about accidentally blocking legitimate email. That concern is valid.

    A company may have several systems sending email, including:

    • Microsoft 365 or Google Workspace
    • Marketing, accounting, support, scheduling, and website platforms

    If those systems are not identified and configured correctly, moving directly to a strict DMARC policy can cause legitimate messages to fail. The right approach is to monitor first, fix authentication issues, and then gradually increase enforcement. A proper implementation usually happens in stages.

    First, your IT provider should inventory every platform that sends email using your domain. SPF and DKIM should then be configured for each legitimate service.

    Next, DMARC reporting should be enabled so your team can review authentication results and identify unknown senders.

    Once legitimate traffic is consistently passing authentication, the DMARC policy can be moved from monitoring to quarantine. After additional review, it can be changed to reject. This staged approach reduces risk while steadily improving protection.

    There are common pitfalls to implementing these protections in your business. One of the most common mistakes is having multiple SPF records. A domain should generally have only one SPF record, with all authorized senders included in that record. Another common problem is exceeding SPF lookup limits. Adding too many services can cause SPF validation to fail, even when the record appears correct. Other issues include expired DKIM keys, marketing systems that were never authenticated, and DMARC records that remain in monitoring mode for years.

    Email authentication is not a one-time project. It should be reviewed whenever your company adds or removes a system that sends email. Does DMARC stop every scam email ? No, no single technology stops every threat.

    DMARC is highly effective at reducing direct domain spoofing, but attackers may still register lookalike domains. For example, they could replace a letter in your company name or add a word such as “billing” or “support.” Attackers can also compromise real employee mailboxes through phishing, stolen passwords, or weak multifactor authentication.

    That is why DMARC should be part of a broader email security strategy that includes:

    • Multifactor authentication and strong account security
    • Employee training, email filtering, and ongoing monitoring

    DMARC protects your domain’s identity. It does not replace the need to secure the accounts and people using it. When scammers impersonate your domain, the damage can extend beyond a single fraudulent email. Customers may lose confidence in your company. Employees may become hesitant to trust legitimate messages. Vendors may question payment requests, and your domain’s reputation may suffer with major email providers.

    SPF, DKIM, and DMARC help prove that legitimate email is really coming from your business. They also make it much harder for attackers to use your domain as a disguise.

    Valley Techlogic can review your current email authentication setup, identify unauthorized sending sources, configure SPF and DKIM correctly, and help move your DMARC policy toward full enforcement without disrupting legitimate email. Do not wait until a customer receives a fake invoice or an employee responds to a fraudulent executive request. Protect your domain before a scammer decides to use it, reach out for a consultation today to get started.

    This article was powered by Valley Techlogic, leading provider of trouble free IT services for businesses in California including Merced, Fresno, Stockton & More. You can find more information at https://www.valleytechlogic.com/ or on Facebook at https://www.facebook.com/valleytechlogic/ . Follow us on X at https://x.com/valleytechlogic

  • How much does it cost to wire a small office? We break it down

    How much does it cost to wire a small office? We break it down

    Whether you are opening a new office, renovating an existing space, or replacing an improvised network, structured cabling is one of the most important parts of the project. It is also one of the hardest expenses to estimate without seeing the building. A business owner might hear that network cabling costs a certain amount “per drop,” but that number rarely tells the whole story. The type of cable, number of connections, condition of the building, network closet, testing requirements, and working environment can all affect the final price. Here is our breakdown on what a small businesses should expect when budgeting for a professional network cabling installation.

    First you need a network drop, a network drop is a permanent cable connection installed between the central network location and a device location elsewhere in the building. One end of the cable is usually terminated at a patch panel in the network rack. The other end is terminated at a wall jack, ceiling location, floor box, or another designated connection point.

    A single office may need separate drops for:

    • Desktop computers, VoIP phones, printers, wireless access points, security cameras, conference-room equipment, door access systems, and other connected devices
    • Redundant connections, future equipment, relocated workstations, or devices that require dedicated network access

    The number of employees does not necessarily equal the number of network drops. A ten-person office may need 20, 30, or more connections once phones, printers, wireless access points, cameras, conference rooms, and future growth are considered.

    You may be wondering what a network drop costs. As a broad 2026 planning range, straightforward commercial Cat6 installations often cost approximately $250 to $350 per drop. Cat6A installations, difficult cable routes, finished-wall work, and smaller service-call projects can cost $400 to $500 or more per drop. It’s important to note these are budgeting ranges, not guaranteed prices.

    A contractor installing 40 drops during an office renovation may charge less per connection than a contractor installing two cables above a finished executive office. Multiple cables that share the same pathway can usually be installed more efficiently than individual cables scattered throughout a building. The cable itself is often one of the least expensive parts of the project. Skilled labor, building access, termination, labeling, testing, equipment, and documentation account for much of the total cost. The biggest factors that effect cabling costs are:

    1. Number of Network Drops

    Larger projects usually have a lower cost per drop because setup, travel, equipment, and project management costs are distributed across more connections.

    Small projects can appear expensive on a per-drop basis because the installer still needs to mobilize a technician, bring tools and materials, access the network closet, route the cable, terminate both ends, test the connection, and document the work.

    2. Cable Type

    Cat6 is a common choice for small business offices. It supports Gigabit Ethernet at the full channel distance and can support 10 Gigabit Ethernet over shorter distances when properly installed. Cat6A is designed to support 10 Gigabit Ethernet over longer runs, but the cable is thicker, harder to route, and generally more expensive to terminate. It can make sense for high-performance workstations, servers, uplinks, wireless access points, or environments where long-term capacity is especially important. Installing the most expensive cable everywhere is not always necessary. The better approach is to select the cable category based on the business’s equipment, expected network speeds, building layout, and growth plans.

    3. Building Construction

    A modern office with accessible drop ceilings and open cable pathways is usually easier to wire than a building with solid ceilings, concrete walls, fire barriers, finished drywall, or limited access between floors. Older and historic buildings can require creative routing, additional labor, surface-mounted raceway, core drilling, or coordination with building management. Warehouses and manufacturing environments may require lifts, conduit, protective pathways, industrial-rated components, or work around active operations.

    4. Plenum-Rated Cable

    Some commercial spaces require plenum-rated cable when wiring is installed in air-handling spaces. Plenum cable uses materials designed to limit smoke and flame propagation. It generally costs more than standard riser-rated cable. The appropriate cable depends on the building, cable pathway, applicable code requirements, and instructions from the authority having jurisdiction. Using the wrong cable can create safety, inspection, and compliance problems, so this is not an area where a contractor should guess.

    5. Network Rack and Patch Panel

    The cabling must terminate somewhere, a professional project may require a wall-mounted rack or floor-standing cabinet, patch panels, cable managers, shelves, rack-mounted power distribution, grounding, patch cables, and an uninterruptible power supply. An existing rack may also need to be reorganized or replaced. A network closet filled with unlabeled cables, stacked equipment, household power strips, and unsupported switches can add time and cost to the project.

    6. Workstation and Device Locations

    Running four cables to one conference room is usually more efficient than running four cables to separate offices on opposite sides of the building. Ceiling-mounted wireless access points and security cameras can require longer routes, ladders, lifts, special mounting hardware, or work outside normal business hours. The installer must also account for furniture placement, cubicles, floor boxes, reception desks, wall-mounted displays, conference tables, printers, and other equipment.

    7. Testing and Certification

    Every installed cable should be tested, basic testing confirms that the conductors are terminated correctly and that the cable is connected from end to end. More advanced certification testing verifies that the completed link meets the performance requirements of the specified cabling standard. Certification testing and detailed test reports may increase the project price, but they provide useful evidence that the cabling was installed correctly. This is especially important for larger projects, new construction, warranty-backed installations, or environments where network reliability is critical.

    8. Labeling and Documentation

    Every connection should be labeled consistently at the wall jack and patch panel. The customer should also receive documentation showing where the drops are located and how they correspond to the rack. This makes future troubleshooting, equipment replacement, office moves, and network upgrades much easier. A cheap installation with no labels or documentation often becomes an expensive problem later.

    9. Permits, Firestopping, and Building Requirements

    Commercial properties may have rules governing contractor access, insurance, working hours, ceiling access, cable pathways, firestopping, and cleanup. Some projects require permits or inspections. Penetrations through rated walls may need approved firestop materials and proper documentation. These requirements can affect both the project schedule and final price.

    10. After-Hours Work

    Some businesses cannot have technicians working above employees, moving ceiling tiles, using ladders, or temporarily interrupting network equipment during the workday. Evening, overnight, or weekend installation may be available, but it can increase labor costs. Businesses should discuss scheduling requirements before approving the project.

    These examples are broad planning estimates rather than formal quotes. A small professional office may need 8 to 12 Cat6 drops for workstations, phones, a printer, and one or two wireless access points. The structured cabling portion might fall between $1,200 and $3,000, depending on the building and project conditions. A rack, patch panel, network equipment, UPS, or difficult cable routes would increase the total.

    An office with 10 to 20 employees may need 20 to 30 drops once workstations, phones, printers, conference rooms, wireless access points, and spare connections are included. A planning range might be $3,000 to $7,500 for the cabling itself. The complete network project could cost more once switching, Wi-Fi, firewall, rack equipment, labor, configuration, and documentation are included.

    A larger office with 40 to 60 drops might budget approximately $6,000 to $15,000 or more for structured cabling. Costs can rise significantly when the project includes Cat6A, fiber between network closets, security cameras, access control, difficult pathways, lifts, conduit, after-hours work, or extensive rack construction.

    We should also note network cabling is not the same as a complete network installation, A cabling quote may cover only the permanent cable runs, wall jacks, patch-panel terminations, testing, and labels. A complete office network may also require:

    • A business-grade firewall, managed switches, wireless access points, rack or cabinet, patch panels, patch cables, UPS equipment, cameras, access control components, and installation hardware
    • Network configuration, VLANs, guest Wi-Fi, security policies, monitoring, documentation, equipment mounting, internet cutover coordination, and post-installation support

    This distinction matters when comparing proposals. One contractor may quote only the cable installation, while another may quote a fully designed and operational network. The less expensive proposal may simply include less work. It is difficult to provide an accurate cabling quote from a floor plan or employee count alone. A site assessment allows the installer to inspect the network closet, ceiling access, wall construction, cable pathways, device locations, building requirements, and existing infrastructure.

    It also gives the business an opportunity to identify future needs before installation begins. Adding a few extra cables during a planned project is usually easier and less expensive than calling a contractor back six months later. During the assessment, the installer should confirm the number and location of drops, cable category, rack requirements, testing method, labeling format, working hours, access restrictions, and any optional work.

    So how do you compare cabling quotes with all of this information in mind? Do not compare proposals based only on the total price or advertised price per drop. Confirm whether each quote includes the cable, jacks, faceplates, patch-panel terminations, patch panel, rack hardware, testing, labels, cleanup, documentation, permits, and firestopping.


    Also check whether the contractor is proposing copper-clad aluminum cable. Copper-clad aluminum is cheaper than solid-copper cable, but it is not an appropriate substitute for standards-compliant horizontal network cabling. A professional proposal should clearly describe what is included, what is excluded, and how changes will be handled.

    Also, when planning should you include extra drops? In many cases, yes. Office layouts change. Employees move. Conference rooms gain new equipment. Security cameras are added. Wireless access points are upgraded. Printers are relocated. New internet or phone equipment may need additional connections. Installing spare drops in strategic locations can reduce future service calls and prevent temporary cables from being routed across floors, through doorways, or along walls. The goal is not to install unnecessary cable everywhere. It is to think beyond the equipment that happens to be present today.

    The bottom line is, for preliminary budgeting, many small businesses can expect professional commercial network cabling to cost approximately $150 to $350 per drop, with the final price determined by cable type, building conditions, number of drops, routing difficulty, testing requirements, and project scope.

    A properly designed cabling system should last through multiple generations of computers, switches, wireless access points, and internet service upgrades. Cutting corners may lower the initial invoice, but poor termination, incomplete testing, missing labels, and inadequate pathways can create years of reliability and support problems.

    The best way to establish an accurate budget is to schedule a site assessment and receive a written proposal based on the actual building, equipment, and business requirements. A good cabling project does more than connect devices. It creates a reliable foundation for the entire business network.

    At Valley Techlogic, project work is another core facet of the services we offer to businesses in our community. We have low voltage technicians available with 15+ years of experience to help you plan your networking project from start to finish and identify any steps other providers may miss. Learn more today through a consultation.

    This article was powered by Valley Techlogic, leading provider of trouble free IT services for businesses in California including Merced, Fresno, Stockton & More. You can find more information at https://www.valleytechlogic.com/ or on Facebook at https://www.facebook.com/valleytechlogic/ . Follow us on X at https://x.com/valleytechlogic

  • The Pentagon announced an ‘immediate suspension’ of CMMC phase II requirements, what this means and how to proceed

    The Pentagon announced an ‘immediate suspension’ of CMMC phase II requirements, what this means and how to proceed

    The Department of Defense (now War under President Trump) announced this week they’re suspending all Cybersecurity Maturity Model Certification (CMMC) Phase II requirements effectively immediately. The requirements were originally scheduled to come into effect November 10th, 2026, these requirements would have required the DoD to be involved in third-party cybersecurity assessments involving sensitive but classified data. Phase requirements that require a CMMC self-assessment and began last November will stay in place as of the time being.

    The Pentagon announced they will be doing a “top-to-bottom” review of the CMMC certification program over the next 60 days, the memo released by DoD Chief Information Officer Kristin Davies suggests that the program has come into conflict with Defense Secretary Pete Hegseth’s initiatives to eliminate government bureaucracy and enable more innovation by removing guardrails.

    “The current iteration of the Cybersecurity Maturity Model Certification (CMMC) program, while intended to enhance security, imposes significant and often prohibitive burdens on the Defense Industrial Base (DIB), particularly the small and non-traditional businesses that are the engine of American innovation,” Davies wrote. “While cybersecurity is essential, administrative compliance cannot come at the cost of warfighting capability and industrial base growth.” – DoD Chief Information Officer Kristin Davies

    In addition to removing the November deadline for third-party assessments the memo suspends all pending and future CMMC milestones “until further notice”.  Before this announcement some DoD offices had already began conducting third-party assessments in advance. It’s clear from the memo that this move is intended to remove hindrances from DIB contractors and speed up innovation and capacity within that base to further the goals of the current administration.

    However, this change has left many defense contractors uncertain how to proceed. The CMMC program in general has experienced a host of changes since it’s inception in 2010 under an executive order from President Obama. It’s goal was to provide a standard for cyber security for defense contractors who handle controlled unclassified data (CUI) and it wasn’t until 2019 that development on the program actually began.

    Self-attestation was originally only meant for very small contractors handling limited CUI while larger contractors and more complete DoD contracts would eventually require third-party assessments and more rigorous levels of cyber security hygiene. Even the DoD itself failed to measure up to the tough requirements outlined in the program.

    The CMMC assessment industry has also been booming since the program was implemented and this news will leave many of those outfits in limbo, DoD contractors were using the C3PAO assessment to be officially CMMC certified and for CMMC audits. CMMC C3PAO assessors have received specialized training to be authorized to conduct CMMC assessments and guide organizations through their CMMC journey.

    CMMC shares overlap with NIST 800-171 compliance (NIST is also the inspiration for many other cybersecurity frameworks such as CIS) and while the third-party audit portion may be paused at the moment, we still recommend businesses strive to meet compliance with their chosen cyber security framework just as a matter of good practice.

    Cyber security framework compliance helps your business:

    1. Reduces the chance of a successful cyberattack
      A framework like the NIST Cybersecurity Framework helps a business identify weak passwords, missing updates, excessive permissions, unsecured devices, and other common gaps before attackers exploit them.
    2. Limits damage when an incident occurs
      Clear access controls, network protections, backups, endpoint security, and incident-response procedures can keep a compromised account or computer from turning into a business-wide disaster.
    3. Improves detection and response time
      Logging, monitoring, alerting, and documented escalation procedures help the business recognize suspicious activity sooner and respond consistently instead of improvising during a crisis.
    4. Protects business operations and customer data
      The framework encourages reliable backups, recovery testing, data classification, vendor oversight, and continuity planning. These controls help the company continue operating after ransomware, equipment failure, or account compromise.
    5. Builds trust and supports compliance requirements
      Following a recognized framework demonstrates that cybersecurity is being managed systematically. This can help with cyber-insurance applications, customer security questionnaires, contractual requirements, audits, and regulated-data obligations.

    As a managed service provider, we help our clients meet compliance requirements for NIST, CMMC, CIS, HIPAA, WISP and more. It can be difficult for a small or medium-sized business to tackle and maintain the security features implemented alone, we suggest working with a trusted partner in this process.

    For CMMC contractors, at this point it is too early to know what will happen in the future or with the program in general but the protections that have been put in place to meet the requirements are still a net positive for your business’s security posture. If scaling up your business’s security goals and addressing compliance requirements is on your radar for 2026, Valley Techlogic can be your trusted partner in the process. Learn more today through a consultation.

    This article was powered by Valley Techlogic, leading provider of trouble free IT services for businesses in California including Merced, Fresno, Stockton & More. You can find more information at https://www.valleytechlogic.com/ or on Facebook at https://www.facebook.com/valleytechlogic/ . Follow us on X at https://x.com/valleytechlogic

  • We all know MFA is important, but many users are expressing symptoms of “MFA fatigue”

    We all know MFA is important, but many users are expressing symptoms of “MFA fatigue”

    Multi-factor authentication, commonly called MFA, has become one of the most important protections a business can put in place. It helps stop attackers from getting into company accounts even when a password has been stolen, guessed, reused, or leaked in a breach. However, there is a real problem many businesses are running into: people are tired of MFA prompts.

    Employees are juggling email, Teams, payroll systems, accounting tools, CRMs, file sharing platforms, vendor portals, and remote access systems. When every app seems to ask for another code, another approval, or another phone notification, MFA can start to feel like a daily annoyance instead of an important security control.

    That frustration is understandable. But turning MFA off, weakening it, or only applying it to a few users is not the answer. The right answer is to build an MFA strategy that protects the business without making employees miserable. Passwords are no longer enough to protect business accounts. NIST notes that MFA adds protection by requiring more than just a username and password, using a combination of something you know, something you have, or something you are.

    For a small business, one compromised account can create a chain reaction. If an attacker gets into email, they may be able to reset passwords for other services, read invoices, impersonate executives, redirect payments, access sensitive files, or launch phishing attacks against clients and vendors. That is why MFA matters so much. It creates a second barrier between a stolen password and your business data.

    The problem is that not all MFA is equally strong. Microsoft has warned that traditional MFA methods like SMS codes, email one-time passcodes, and basic push notifications are becoming less effective against modern attackers, especially when attackers use phishing, social engineering, or MFA bombing to wear users down. In other words, the goal should not simply be “turn on MFA.” The goal should be to use the right kind of MFA in the right places.

    First let’s identify what we mean by “MFA fatigue”, MFA fatigue can mean two different things. first is normal user frustration. Employees get annoyed when they are prompted too often, especially if prompts feel random, repetitive, or disruptive.

    The second is an actual attack technique. In an MFA fatigue or “push bombing” attack, a criminal already has the user’s password and repeatedly sends MFA approval prompts, hoping the user eventually taps “approve” just to make the noise stop. Microsoft specifically identifies user fatigue and MFA bombing as ways attackers bypass weaker authentication methods. This is why businesses need to treat MFA fatigue seriously. It is both a usability issue and a security issue.

    Some businesses technically have MFA enabled, but only in a limited or inconsistent way. That can create a false sense of security. Common issues include:

    • MFA is required for some employees but not all.
    • Admin accounts are not protected with stronger authentication.
    • Email-based MFA is used as the primary method.
    • SMS codes are allowed for sensitive accounts.
    • Employees receive push prompts without number matching or location context.
    • Legacy authentication methods are still allowed.
    • Former employees, contractors, or shared accounts are not reviewed.
    • MFA recovery processes are informal or undocumented.

    These gaps matter, attackers usually do not need access to every account. They only need access to one useful account. A compromised mailbox can lead to business email compromise, fraudulent payment requests, client impersonation, data theft, or ransomware. For businesses that work with regulated data, financial information, legal documents, healthcare information, or client confidential records, the risk is even higher.

    A good MFA strategy should be strong, simple, and consistent. It should protect the business while reducing unnecessary friction for users. First, require MFA for every user. MFA should not be limited to owners, managers, or employees who “handle sensitive information.” In a modern cloud environment, almost every account has some level of business risk.

    Second, prioritize stronger authentication methods. App-based MFA is better than SMS or email-based verification, but phishing-resistant methods are better still. Microsoft describes passkeys as phishing-resistant credentials that can serve as an MFA method, and notes that they can reduce prompts while improving security.

    For most small businesses, a practical MFA roll out path looks like this:

    1. Eliminate email-based MFA wherever possible.
    2. Move users to an authenticator app with number matching.
    3. Use passkeys or security keys for administrators, finance users, executives, and anyone with access to sensitive systems.
    4. Keep SMS only as a temporary fallback, not the preferred method.
    5. Document account recovery so users are not locked out when phones are replaced or lost.

    Microsoft also notes that number matching is critical to reducing accidental MFA approvals, especially as MFA fatigue attacks increase. The best MFA setup is not the one that prompts users constantly. The best setup is the one that prompts users when it actually matters.

    Small businesses can reduce MFA fatigue by using smarter access policies. For example, users may not need to be prompted every single time they access a trusted app from a managed device in a normal location. But they should absolutely be challenged when signing in from a new device, an unusual location, a risky session, or a sensitive admin portal. This is where conditional access policies can help. Instead of treating every login the same, conditional access allows the business to apply stronger controls based on risk.

    A good policy may consider:

    • Who the user is
    • What app they are accessing
    • Whether the device is trusted
    • Whether the sign-in location is expected
    • Whether the account has administrative privileges
    • Whether the session appears risky

    This gives employees a smoother daily experience while still applying stronger controls when the risk is higher. MFA is not just a technical setting. Employees need to understand what to do when they receive a prompt. The rule should be simple: never approve an MFA prompt you did not initiate.

    If an employee receives an unexpected MFA prompt, that may mean someone already has their password. They should deny the request and report it immediately. Users should not ignore it, approve it, or assume it is a glitch. Training does not need to be complicated. A short, clear explanation is usually enough:

    “MFA prompts should only appear when you are actively signing in. If you get a prompt you did not request, deny it and contact IT.” That one rule can stop a serious  incident.

    Also, Administrative accounts deserve extra protection. These accounts can often change security settings, reset passwords, access sensitive data, create new users, modify mail flow, and approve applications. For admin accounts, stronger MFA should be required. Passkeys, FIDO2 security keys, or other phishing-resistant methods are strongly preferred. NIST also recommends phishing-resistant authentication for sensitive applications and users with elevated privileges. Business owners, finance users, HR users, and anyone who can approve payments or access confidential client data should also be considered high-risk.

    Special consideration should also be taken when addressing new employees. MFA should be built into onboarding, role changes, and offboarding. When a new employee starts, they should be enrolled in the correct MFA method from day one. When someone changes roles, their access and authentication requirements should be reviewed. When someone leaves the company, their sessions should be revoked, their account should be disabled, and their access should be removed promptly.

    This is especially important for small businesses because responsibilities often overlap. One person may handle finance, HR, operations, and vendor relationships. That makes account security even more important.

    The bottom line is MFA fatigue is real. Employees are tired of excessive prompts, confusing login flows, and security tools that get in the way of work, but avoiding MFA is not a realistic option. The risk of account compromise, payment fraud, data theft, and business disruption is too high. The better approach is to modernize MFA. Require it consistently, move away from weaker methods, use phishing-resistant authentication where possible, reduce unnecessary prompts, and train users to recognize suspicious activity.

    Security should not feel like punishment. Done correctly, MFA can become a normal, low-friction part of doing business safely. If your business is still relying on passwords alone, email-based MFA, SMS codes, or inconsistent MFA policies, now is the time to review your setup. Valley Techlogic can help evaluate your current Microsoft 365 and cloud security configuration, identify gaps, and build an MFA strategy that protects your business without overwhelming your users. Learn more today with a consultation.

    This article was powered by Valley Techlogic, leading provider of trouble free IT services for businesses in California including Merced, Fresno, Stockton & More. You can find more information at https://www.valleytechlogic.com/ or on Facebook at https://www.facebook.com/valleytechlogic/ . Follow us on X at https://x.com/valleytechlogic

  • Rolling out Microsoft 365 Copilot in your office environment? Here are 8 permissions to pay attention to keep your data safe

    Rolling out Microsoft 365 Copilot in your office environment? Here are 8 permissions to pay attention to keep your data safe

    Microsoft 365 Copilot can be a major productivity boost, but it also changes how quickly employees can find information across your organization. That is both the opportunity and the risk.

    Copilot does not magically bypass Microsoft 365 permissions. Microsoft states that Copilot surfaces organizational data only when the user already has permission to view it. The real issue is that many businesses already have overshared files, old SharePoint sites, public Teams, broad group permissions, and years of forgotten access sitting in the background. Copilot can make existing access much easier to discover.

    Before you roll Copilot out broadly, take a close look at these eight permission areas.

    1. SharePoint site permissions

    SharePoint is one of the first places to review because so much company data lives there. If a department site, project site, or old document library has overly broad access, Copilot may be able to reference that content for anyone who already has permission.

    Pay special attention to sites that contain HR files, financial documents, contracts, legal records, customer data, intellectual property, internal strategy, or acquisition discussions. Microsoft recommends preparing SharePoint governance before enabling Copilot, including reducing accidental oversharing and reviewing access at the organization and site level.

    2. OneDrive sharing permissions

    OneDrive often becomes a hidden data swamp. Employees share files for convenience, links get forwarded, and old access is rarely reviewed. That can become a problem when Copilot is introduced.

    The most common issues are files shared with “Anyone with the link,” files shared broadly across the company, and folders that were shared years ago for a short-term need but never cleaned up. Review OneDrive sharing policies, disable overly permissive link defaults, and encourage users to share through controlled groups instead of open links whenever possible.

    3. Microsoft Teams membership

    Teams permissions matter because each Team is backed by a Microsoft 365 Group and often a connected SharePoint site. If someone is added to a Team, they may also gain access to files, conversations, notebooks, meeting content, and shared resources tied to that workspace.

    This is where businesses can get surprised. A user may have been added to a Team for one project two years ago and still have access to everything in it today. Review Team owners, members, guests, private channels, shared channels, and archived Teams before enabling Copilot for everyone.

    4. Microsoft 365 Group permissions

    Microsoft 365 Groups control access across multiple services, including SharePoint, Teams, Outlook, Planner, and more. If your groups are messy, Copilot readiness will be messy too.

    Look for groups with vague names like “All Staff,” “Operations,” “Management,” or “Projects.” Then confirm whether the membership still matches the sensitivity of the content connected to that group. Group cleanup is not glamorous, but it is one of the most practical ways to reduce accidental data exposure before a Copilot rollout.

    5. “Everyone” and “Everyone except external users” access

    Broad permission groups are convenient, but they can create real risk. Many Microsoft 365 environments have content shared with company-wide groups because it was easy at the time.

    That might be fine for an employee handbook. It is not fine for payroll exports, leadership notes, customer agreements, legal files, or confidential project folders. Before enabling Copilot widely, search for content and sites granted to broad groups. Remove that access where it is not truly necessary.

    6. Guest and external user permissions

    External sharing is another area to review carefully. Vendors, contractors, consultants, former partners, and temporary collaborators may still have access to Teams, SharePoint sites, and OneDrive files.

    Copilot does not remove the need for basic access hygiene. If external users still have access to internal content, that is a permission problem whether Copilot is enabled or not. Review guest accounts, external sharing links, inactive guests, shared channels, and contractor access. Remove access that is no longer required.

    7. Sensitivity label permissions

    Sensitivity labels from Microsoft Purview can classify and protect documents, emails, Teams, Microsoft 365 Groups, SharePoint sites, and other collaborative spaces. Labels can help enforce encryption, privacy controls, external sharing restrictions, and container-level protection depending on how they are configured.

    This matters for Copilot because sensitive data needs more than “please do not open this” protection. It needs technical controls that travel with the data. At  minimum, consider labels for confidential company data, client data, financial data, HR data, regulated data, and executive-only content.

    8. Admin, compliance, and governance permissions

    Do not forget the people who manage the system. Global admins, SharePoint admins, Teams admins, Exchange admins, security admins, compliance admins, and Purview roles should all follow least-privilege access.

    Microsoft’s Zero Trust guidance for Microsoft 365 Copilot emphasizes identity, device health, least privilege, data protection, and monitoring as part of a secure rollout. In plain English: do not give people admin rights unless they truly need them. Review privileged roles, remove stale admins, require MFA, use role-based access control, and monitor activity.

    A safer Copilot rollout begins with permissions, Microsoft 365 Copilot is not just another app to license. It is a visibility layer over the data your users can already access. That means a safe rollout should start before the first license is assigned. Review SharePoint, OneDrive, Teams, Microsoft 365 Groups, external access, broad sharing links, sensitivity labels, and admin roles first.

    The goal is not to slow your business down. The goal is to make sure Copilot helps employees find the right information without accidentally exposing the wrong information.

    For most small and midsize businesses, the smartest path is a phased rollout:

    • Start with a small pilot group, clean up permissions, and test what Copilot can surface.
    • Expand only after your most sensitive sites, groups, and sharing policies have been reviewed.

    Copilot can be a powerful tool, but only if your Microsoft 365 environment is ready for it. Clean permissions are not just an IT best practice anymore. They are the foundation for using AI safely at work. If you need help managing and deploying Copilot in your business, Valley Techlogic is here for you. We have experience deploying Copilot for our clients as well as using it day to day in our own organization. We can help you establish a plan and a timeline for your Copilot rollout, reach out today for more information.

    This article was powered by Valley Techlogic, leading provider of trouble free IT services for businesses in California including Merced, Fresno, Stockton & More. You can find more information at https://www.valleytechlogic.com/ or on Facebook at https://www.facebook.com/valleytechlogic/ . Follow us on X at https://x.com/valleytechlogic

  • Are you keeping track of breaches that are happening with your vendors? What small businesses can learn from the Klue/Salesforce breach

    Are you keeping track of breaches that are happening with your vendors? What small businesses can learn from the Klue/Salesforce breach

    When most small businesses think about cybersecurity, they think about their own systems first. Are our computers protected? Are our passwords strong? Is our email secure? Do we have backups?

    Those are all important questions. But there is another question that deserves just as much attention: Are the vendors we rely on putting our business data at risk?

    The recent Klue/Salesforce breach is a good reminder that small businesses do not operate in a vacuum. Even if your own network is locked down, your data may still live in someone else’s system. It may be stored in your CRM, marketing platform, accounting software, ticketing system, quoting tool, password manager, payroll provider, or any number of cloud applications connected to each other behind the scenes.

    In this case, public reporting indicates that attackers abused access tied to Klue, a competitive intelligence platform, to reach data connected through Salesforce environments. The important lesson is not just “Salesforce” or “Klue.” The bigger lesson is that connected vendor platforms can become pathways into sensitive business data.

    For small businesses, that matters a lot.

    You may not have a full-time security team watching every vendor announcement. You may not have a compliance department tracking every software integration. But you probably do have customer information, employee information, invoices, quotes, sales notes, passwords, emails, support tickets, or financial records spread across multiple vendors.

    That means vendor breach monitoring needs to be part of your normal security routine. A vendor breach does not have to involve your internal server, your firewall, or your employee laptops to affect you.

    If a third-party platform you use is compromised, attackers may be able to access customer records, support cases, contact lists, documents, billing details, or internal notes. Even when passwords are not exposed, stolen business data can still be used for phishing, impersonation, fraud, social engineering, or targeted scams.

    This is especially dangerous because vendor-related phishing can look very believable. If an attacker knows who your customers are, what services they use, who manages their account, or what projects are active, they can write emails that sound legitimate.

    For a small business, the damage can be immediate. Customers lose trust. Staff waste time investigating. Leadership has to figure out whether notifications are required. And if nobody was watching for the breach in the first place, the business may learn about it too late.

    Three steps small businesses can take to monitor vendor breaches

    1. Keep a simple vendor and data inventory

    You cannot monitor vendor risk if you do not know which vendors have access to your data.

    Start with a simple spreadsheet or shared document. It does not need to be complicated. List every cloud service your business uses, what kind of data it stores, who owns the relationship internally, whether it connects to other systems, and how critical it is to your operations.

    At minimum, track:

    • Vendor name
    • Type of data stored
    • Admin owner
    • Login method
    • Connected integrations
    • Business impact if breached

    Pay special attention to tools connected to email, CRM, file storage, accounting, remote access, security, payroll, and customer support. These systems tend to hold valuable data or provide access to other platforms.

    The goal is simple: if a breach happens, you should be able to quickly answer, “Do we use this vendor, what data is there, and what should we check first?”

    1. Subscribe to vendor security notices and monitor trusted sources

    Many small businesses only hear about vendor breaches from social media, a random news article, or a customer asking whether they are affected. That is not good enough. For your most important vendors, subscribe to their security advisories, status pages, email alerts, and trust center updates. If they offer a security notification list, use it. If they have a status page, bookmark it. If your vendor has an admin portal with security notices, make sure someone checks it.

    You should also monitor reliable cybersecurity news sources and breach notification feeds for vendors you depend on. This does not mean doom-scrolling every day. It means assigning someone to keep a light but consistent eye on the tools that matter most to the business.

    For managed IT clients, this is also an area where your IT provider can help. Vendor breach monitoring should not be treated as an occasional panic response. It should be part of normal operational security.

    1. Have a vendor breach response checklist before something happens

    When a vendor breach hits the news, the worst time to build your response process is after the fact. Small businesses should have a short checklist ready. When a vendor announces a breach, your team should know how to assess whether you are affected and what actions to take.

    A practical checklist should include:

    • Confirm whether your business uses the vendor or affected integration
    • Review what data the vendor stores or can access
    • Check vendor advisories for affected dates, systems, and data types
    • Revoke or rotate API keys, OAuth tokens, passwords, and connected app permissions where appropriate
    • Review admin accounts and recent login activity
    • Look for suspicious email, CRM, file, or support activity
    • Warn staff about phishing attempts tied to the incident
    • Determine whether customers, employees, insurers, legal counsel, or regulators need to be notified
    • Document what was reviewed and what actions were taken

    We have a simple template for this you can grab below that also covers breaches within your business:

    This does not need to be a 40-page incident response plan. It just needs to be clear enough that your team can act quickly and calmly. The big takeaway is that security does not stop at your own front door.

    Modern businesses are built on connected cloud platforms. That brings huge benefits, but it also creates shared risk. A vendor integration, API token, or connected app can become a weak link, even when your own systems are not directly compromised. Small businesses should not respond by abandoning cloud tools, that’s not realistic. The better response is to know which vendors matter, track where your data lives, monitor for breach notices, and have a plan for what to do when something goes wrong. You do not need enterprise-level complexity to do this well. You need consistency, ownership, and a clear process.

    Vendor breaches are no longer rare edge cases. They are part of doing business in a cloud-connected world. The businesses that handle them best are not the ones that never use vendors. They are the ones that know their vendors, monitor their risk, and respond quickly when the situation calls for it. At Valley Techlogic, we act as a vendor liaison for clients and can help you monitor and respond to breaches even if they’re not happening to your organization directly. Learn more today through a consultation.

    This article was powered by Valley Techlogic, leading provider of trouble free IT services for businesses in California including Merced, Fresno, Stockton & More. You can find more information at https://www.valleytechlogic.com/ or on Facebook at https://www.facebook.com/valleytechlogic/ . Follow us on X at https://x.com/valleytechlogic