Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Microsoft Authenticator is about to wipe work accounts from jailbroken/rooted phones automatically πŸ‘.

Microsoft Authenticator is about to wipe work accounts from jailbroken/rooted phones automatically πŸ‘.

Scheduled Pinned Locked Moved Uncategorized
66 Posts 44 Posters 137 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • merill@infosec.exchangeM merill@infosec.exchange

    Wow. So a LOT of you folks are not happy.

    The good news is your org can still allow you to use passkeys and other Authenticator apps.

    dodecahedrus@mastodon.socialD This user is from outside of this forum
    dodecahedrus@mastodon.socialD This user is from outside of this forum
    dodecahedrus@mastodon.social
    wrote last edited by
    #40

    @merill tell that to my org that only allows the authenticator app.

    1 Reply Last reply
    0
    • smn@l3ib.orgS smn@l3ib.org

      @merill what exactly is the threat model that makes a rooted device risky for an authenticator app?

      cwg1231@defcon.socialC This user is from outside of this forum
      cwg1231@defcon.socialC This user is from outside of this forum
      cwg1231@defcon.social
      wrote last edited by
      #41

      @smn @merill I’d like to know as well.

      1 Reply Last reply
      0
      • crazyeddie@mastodon.socialC crazyeddie@mastodon.social

        @thaodan @fluffykittycat @merill Why?

        The keys and such associated with the authenticator app should be in a TPM. Something the bootloader can't touch. It can't get the private key to then send it to whoever.

        The bootloader could attack in other ways and get the info you're accessing once logged in, but I don't think it can mess about or bypass the actual security mechanism.

        I think they're trying to sell bullshit here so the ignorant support them as they lock us all down.

        thaodan@mastodon.socialT This user is from outside of this forum
        thaodan@mastodon.socialT This user is from outside of this forum
        thaodan@mastodon.social
        wrote last edited by
        #42

        @crazyeddie @fluffykittycat @merill The bootloader itself isn't the concern but the kernel and what is started afterwards.
        It is a factor even if they only use it as an excuse. Most phones don't have a TPM but an ARM trustzone which can run a software TPM. The problem is that modifying or writing isn't possible low level only over the OS or vendor API's provided.

        1 Reply Last reply
        0
        • merill@infosec.exchangeM merill@infosec.exchange

          Microsoft Authenticator is about to wipe work accounts from jailbroken/rooted phones automatically πŸ‘.

          No IT config needed. πŸ”₯

          3-phase rollout starting Feb 2026:
          ⚠️ Warn β†’ 🚫 Block β†’ πŸ—‘οΈ Wipe

          Let your help desk and security teams know.

          πŸ”— https://support.microsoft.com/en-us/account-billing/jailbreak-root-detection-in-microsoft-authenticator-9f0431bd-675a-4f2d-b8fb-7acd18deaadc

          kontrollierterwahnwitz@sueden.socialK This user is from outside of this forum
          kontrollierterwahnwitz@sueden.socialK This user is from outside of this forum
          kontrollierterwahnwitz@sueden.social
          wrote last edited by
          #43

          @merill I wonder who of the people complaining here do…

          1. … own a rooted / jailbroken phone
          2. … have Microsoft Authenticator installed on this phone
          3. … do use MS Authenticator in combination with an Azure Active Directory account.

          ? drikanis@mstdn.caD 2 Replies Last reply
          1
          0
          • R relay@relay.infosec.exchange shared this topic
          • crazyeddie@mastodon.socialC crazyeddie@mastodon.social

            @thaodan @fluffykittycat @merill Why?

            The keys and such associated with the authenticator app should be in a TPM. Something the bootloader can't touch. It can't get the private key to then send it to whoever.

            The bootloader could attack in other ways and get the info you're accessing once logged in, but I don't think it can mess about or bypass the actual security mechanism.

            I think they're trying to sell bullshit here so the ignorant support them as they lock us all down.

            fluffykittycat@furry.engineerF This user is from outside of this forum
            fluffykittycat@furry.engineerF This user is from outside of this forum
            fluffykittycat@furry.engineer
            wrote last edited by
            #44

            @crazyeddie @thaodan @merill unlocked bootloaders are a moral imperitive. Not to mention all the ewaste created by locked devices not being repurporsable

            thaodan@mastodon.socialT 1 Reply Last reply
            0
            • agowa338@chaos.socialA agowa338@chaos.social

              @merill

              Soo instead of just rooting a phone one needs now to also deploy 38473894 shady scripts and workarounds to hide it from Microsoft Authenticator?

              Congratulation on improving security (NOT).

              fluffykittycat@furry.engineerF This user is from outside of this forum
              fluffykittycat@furry.engineerF This user is from outside of this forum
              fluffykittycat@furry.engineer
              wrote last edited by
              #45

              @agowa338 @merill I'ma have to start carrying around two phones. One for my worksona and one for me

              agowa338@chaos.socialA 1 Reply Last reply
              0
              • fluffykittycat@furry.engineerF fluffykittycat@furry.engineer

                @agowa338 @merill I'ma have to start carrying around two phones. One for my worksona and one for me

                agowa338@chaos.socialA This user is from outside of this forum
                agowa338@chaos.socialA This user is from outside of this forum
                agowa338@chaos.social
                wrote last edited by
                #46

                @fluffykittycat @merill

                And make your employer pay for it. I got my work phone when I refused to put a similarly shitty 2FA app onto my personal one.

                I just said I've a PinePhone with Postmarket OS and I'm not going to buy a new one just for that. + I asked if they'd cover damages for any data deleted because of someone hitting the "wipe phone" button in the MDM that would have come with it accidentally (or on purpose).

                The phone was cheaper for them than continuing the discussion btw πŸ˜›

                1 Reply Last reply
                0
                • silhouette@dumbfuckingweb.siteS silhouette@dumbfuckingweb.site

                  @merill I'm gonna go out on a limb here and say that users that jailbreak their own private device wouldn't use MS Authenticator, and on company devices jailbreak wasn't allowed anyway.

                  fluffykittycat@furry.engineerF This user is from outside of this forum
                  fluffykittycat@furry.engineerF This user is from outside of this forum
                  fluffykittycat@furry.engineer
                  wrote last edited by
                  #47

                  @silhouette @merill people are expected to put this on their personal devices

                  silhouette@dumbfuckingweb.siteS 1 Reply Last reply
                  0
                  • longplay_games@mastodon.gamedev.placeL longplay_games@mastodon.gamedev.place

                    @merill TIL people actually use the MS authenticator

                    fluffykittycat@furry.engineerF This user is from outside of this forum
                    fluffykittycat@furry.engineerF This user is from outside of this forum
                    fluffykittycat@furry.engineer
                    wrote last edited by
                    #48

                    @Longplay_Games @merill not by choice

                    1 Reply Last reply
                    0
                    • fluffykittycat@furry.engineerF fluffykittycat@furry.engineer

                      @silhouette @merill people are expected to put this on their personal devices

                      silhouette@dumbfuckingweb.siteS This user is from outside of this forum
                      silhouette@dumbfuckingweb.siteS This user is from outside of this forum
                      silhouette@dumbfuckingweb.site
                      wrote last edited by
                      #49

                      @fluffykittycat @merill ah, the famous "use your own private resources for the benefit of the company".

                      xarvos@outerheaven.clubX 1 Reply Last reply
                      0
                      • fluffykittycat@furry.engineerF fluffykittycat@furry.engineer

                        @crazyeddie @thaodan @merill unlocked bootloaders are a moral imperitive. Not to mention all the ewaste created by locked devices not being repurporsable

                        thaodan@mastodon.socialT This user is from outside of this forum
                        thaodan@mastodon.socialT This user is from outside of this forum
                        thaodan@mastodon.social
                        wrote last edited by
                        #50

                        @fluffykittycat @merill @crazyeddie Context? Nobody in the thread said that devices where users can't unlock bootloaders are a good thing.
                        Users should just be able to relock it. Locking bootloaders doesn't block flashing it just ensures that only code signing with the owner of the keys in the bootloader can be used, the owner of these keys can be the user.

                        crazyeddie@mastodon.socialC 1 Reply Last reply
                        0
                        • thaodan@mastodon.socialT thaodan@mastodon.social

                          @fluffykittycat @merill @crazyeddie Context? Nobody in the thread said that devices where users can't unlock bootloaders are a good thing.
                          Users should just be able to relock it. Locking bootloaders doesn't block flashing it just ensures that only code signing with the owner of the keys in the bootloader can be used, the owner of these keys can be the user.

                          crazyeddie@mastodon.socialC This user is from outside of this forum
                          crazyeddie@mastodon.socialC This user is from outside of this forum
                          crazyeddie@mastodon.social
                          wrote last edited by
                          #51

                          @thaodan @fluffykittycat @merill Yeah, I can't re-lock my phone or I believe even put the bootloader into write-only. Sucks.

                          fluffykittycat@furry.engineerF 1 Reply Last reply
                          0
                          • merill@infosec.exchangeM merill@infosec.exchange

                            Microsoft Authenticator is about to wipe work accounts from jailbroken/rooted phones automatically πŸ‘.

                            No IT config needed. πŸ”₯

                            3-phase rollout starting Feb 2026:
                            ⚠️ Warn β†’ 🚫 Block β†’ πŸ—‘οΈ Wipe

                            Let your help desk and security teams know.

                            πŸ”— https://support.microsoft.com/en-us/account-billing/jailbreak-root-detection-in-microsoft-authenticator-9f0431bd-675a-4f2d-b8fb-7acd18deaadc

                            renard@equestria.socialR This user is from outside of this forum
                            renard@equestria.socialR This user is from outside of this forum
                            renard@equestria.social
                            wrote last edited by
                            #52

                            @merill what the fuck. You all really want to kill open computing, don't you.

                            1 Reply Last reply
                            0
                            • crazyeddie@mastodon.socialC crazyeddie@mastodon.social

                              @thaodan @fluffykittycat @merill Yeah, I can't re-lock my phone or I believe even put the bootloader into write-only. Sucks.

                              fluffykittycat@furry.engineerF This user is from outside of this forum
                              fluffykittycat@furry.engineerF This user is from outside of this forum
                              fluffykittycat@furry.engineer
                              wrote last edited by
                              #53

                              @crazyeddie @thaodan @merill yeah, locked bootloaders imply the person who purchased it doesn't get full ownership rights over it

                              thaodan@mastodon.socialT 1 Reply Last reply
                              0
                              • bernardsheppard@mastodon.auB bernardsheppard@mastodon.au

                                @merill magisk module to hide root incoming in 3, 2, 1...

                                kuniti_shino@pounced-on.meK This user is from outside of this forum
                                kuniti_shino@pounced-on.meK This user is from outside of this forum
                                kuniti_shino@pounced-on.me
                                wrote last edited by
                                #54

                                @BernardSheppard @merill it exists
                                Just not for android 16

                                bernardsheppard@mastodon.auB 1 Reply Last reply
                                0
                                • merill@infosec.exchangeM merill@infosec.exchange

                                  Wow. So a LOT of you folks are not happy.

                                  The good news is your org can still allow you to use passkeys and other Authenticator apps.

                                  nachof@mastodon.uyN This user is from outside of this forum
                                  nachof@mastodon.uyN This user is from outside of this forum
                                  nachof@mastodon.uy
                                  wrote last edited by
                                  #55

                                  @merill
                                  Wait you were actually saying it as a good thing????

                                  1 Reply Last reply
                                  0
                                  • fluffykittycat@furry.engineerF fluffykittycat@furry.engineer

                                    @crazyeddie @thaodan @merill yeah, locked bootloaders imply the person who purchased it doesn't get full ownership rights over it

                                    thaodan@mastodon.socialT This user is from outside of this forum
                                    thaodan@mastodon.socialT This user is from outside of this forum
                                    thaodan@mastodon.social
                                    wrote last edited by
                                    #56

                                    @fluffykittycat @crazyeddie @merill You have to separate the technical from the ideological part. As long as the user has the control for en- and disable the bootloader signature verification they are perfectly fine. There are parts of the device users shouldn't reflash thou such as the radio configuration.

                                    fluffykittycat@furry.engineerF 1 Reply Last reply
                                    0
                                    • kontrollierterwahnwitz@sueden.socialK kontrollierterwahnwitz@sueden.social

                                      @merill I wonder who of the people complaining here do…

                                      1. … own a rooted / jailbroken phone
                                      2. … have Microsoft Authenticator installed on this phone
                                      3. … do use MS Authenticator in combination with an Azure Active Directory account.

                                      ? Offline
                                      ? Offline
                                      Guest
                                      wrote last edited by
                                      #57

                                      @kontrollierterWahnwitz@sueden.social anyone meeting criteria 1 who are required to use MS Authenticator for work.

                                      1 Reply Last reply
                                      0
                                      • merill@infosec.exchangeM merill@infosec.exchange

                                        Microsoft Authenticator is about to wipe work accounts from jailbroken/rooted phones automatically πŸ‘.

                                        No IT config needed. πŸ”₯

                                        3-phase rollout starting Feb 2026:
                                        ⚠️ Warn β†’ 🚫 Block β†’ πŸ—‘οΈ Wipe

                                        Let your help desk and security teams know.

                                        πŸ”— https://support.microsoft.com/en-us/account-billing/jailbreak-root-detection-in-microsoft-authenticator-9f0431bd-675a-4f2d-b8fb-7acd18deaadc

                                        luana@wetdry.worldL This user is from outside of this forum
                                        luana@wetdry.worldL This user is from outside of this forum
                                        luana@wetdry.world
                                        wrote last edited by
                                        #58

                                        @merill Yikes.

                                        1 Reply Last reply
                                        0
                                        • thaodan@mastodon.socialT thaodan@mastodon.social

                                          @fluffykittycat @crazyeddie @merill You have to separate the technical from the ideological part. As long as the user has the control for en- and disable the bootloader signature verification they are perfectly fine. There are parts of the device users shouldn't reflash thou such as the radio configuration.

                                          fluffykittycat@furry.engineerF This user is from outside of this forum
                                          fluffykittycat@furry.engineerF This user is from outside of this forum
                                          fluffykittycat@furry.engineer
                                          wrote last edited by
                                          #59

                                          @thaodan @crazyeddie @merill why should we expect Microsoft to.honor that? We know they won't

                                          1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups