Microsoft warns Authenticator will block rooted Android and jailbroken iOS, verify if your phone is affected.
I can guarantee this will be a hilarious shitstorm of false positives wasting IT departments’ time, because their detection of it is massively flawed.
At least once a month my - completely stock, and un-rooted - phone tells me I can’t use Outlook/Teams because of root. Every time, a reboot is required to resolve this. One one occasion, TWO reboots.
Ignoring whatever reason Microsoft think they’re blocking this for, it’s going to regularly block regular users, who are not going to stand for it.
microsoft truly hates productivity in the workplace
They somehow trying to eliminate everything they cannot control, funny
I don’t use my account for email anymore or use Windows very often but I just changed the two factor authenticator to Aegis. They make the text to use an alternative authenticator app tiny blue hyperlink text but you can do it confirmed.
Yes. I also switched to Aegis.
Why the fuck would you use a personal phone for work?
Get some cheap alternative and put the authenticator on that phone and say that is your main phone.
2FA is not just for work.
Sure but you can use your own choice of 2FA software for your own stuff
Yeah but that’s the worst app to use if you have a choice. There are a dozen better options.
Better yet, if your work requires you to have Microsoft Authenticator, tell them that they need to provide you with a device capable of using it.
Instead of spending your own money on a burner phone just for that, make your work pay for it.
you don’t just use authenticator for work. anybody who plays Minecraft uses it.
uh no? you can set up any number of mfa methods for a Microsoft account…
Great, what does that have to do with the authenticator supposedly only being for work?
because you said anyone who plays Minecraft had to use it too. you do not. but some people are required to for work. therefore they only have to use it for work. do you get it now or do i need to eli5 it for you more?
I didn’t say anybody who played Minecraft had to use it. You’re just bad at reading. Do I need to walk you through the sentence like you’re five, or are you done beating your chest like a teenager?
you don’t just use authenticator for work. anybody who plays Minecraft uses it.
you’re too dumb to waste my time on anymore. glhf cya
only if the company sets it up that way.
I wont use my personal phone for anything work related except authentication. Since it sits in its own little jail, it’s fine.
I work all over the world and remote in. I have no other work related devices or equipment.
I look at it as a key card from the old days when I had to go into a building. I think that is a pretty trivial use case and doesn’t need them to provide a phone, and in fact I absolutely would not want a device owned by anyone else that I carried around. That is FAR worse.
That said, this change sucks as I will now need to get around this bullshit.
There are a couple Android ports of KeePass. They are open source and won’t care if your phone is rooted.
Does it even support OTP?
Just use https://github.com/beemdevelopment/Aegis on Android.
Yes, both KeePassDX and KeePass2Android support TOTP.
Any password manager that does not support OTP is worthless.
I disagree.
In fact, there is a strong argument to be made that storing your TOTP secrets in the same place as your passwords is bad practice.
You now have a single point of failure that if exploited, could grant an attacker total access to all your accounts.
verify if your phone is affected
No, i don’t use spyware.
How does the tool actually check for this?
Does it just use the Play Integrety API, or does it use some kind of other attestation check?
The need for full root privilege has fallen by the wayside assuming you can trust the OS running on the device. I dont hate this change if I can run a custom ROM that will report that the user does not have root privilege and that the OS has not been modified since boot.
Any app can tell if it has root privileges.
They have to ask for it.
Yes, which is how they know.
Because, obviously, you can’t be a real person if you don’t let the corpos control your device.
“Users of safe and private android versions have laughed at Microslop and their silly software”
Glad I don’t use their app then.
You can jailbreak IOS?
Damn…
So the dream is dead?
Everyone that cares about security or privacy is working on custom android ROMs since there is no actual benefit to Apple hardware or software at this point in history. Plus you save money buying a Pixel device.
Not everyone. Depending where you live there’s no devices available that are compatible with secure custom ROMs (you might be able to deGoogle, but that’s different from being secure).
Your security doesn’t just depend on what flavour of AOSP you decide to use. I’m assuming you’re referring to GrapheneOS, which is only compatible with Pixel devices. Your threat model is also highly relevant. Depending on who you are and what you do, you can be secure on say LineageOS, which will run on a large variety of devices.
yep. it’s sort of dead right now but not completely. in fact, a new bootrom exploit for Xs/11 era devices got released recently, and 11 is still getting supported on latest iOS 27.
I use aegis. Totp works fine. I don’t need push.











