Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Microsoft Authenticator is about to wipe work accounts from jailbroken/rooted phones automatically πŸ‘.

Microsoft Authenticator is about to wipe work accounts from jailbroken/rooted phones automatically πŸ‘.

Scheduled Pinned Locked Moved Uncategorized
66 Posts 44 Posters 137 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • xssfox@cloudisland.nzX xssfox@cloudisland.nz

    @agowa338 @merill and someone attacking will still be able to grab the codes before being wiped because you just stop the app before dumping the data

    agowa338@chaos.socialA This user is from outside of this forum
    agowa338@chaos.socialA This user is from outside of this forum
    agowa338@chaos.social
    wrote last edited by
    #15

    @xssfox @merill

    Ehm, the azure codes are a bit different than the TOTP ones. Their app also has a kinda proprietary auth code format too. I think it is mainly about them. As for all others you literally just have to store a picture of the QR-Code you used to set them up...

    Edit: But yea, it probably will end in there being a shady cracked version of the Microsoft Authenticator App that continues to work on rooted phones...

    xssfox@cloudisland.nzX 1 Reply Last reply
    0
    • merill@infosec.exchangeM merill@infosec.exchange

      Microsoft Authenticator is about to wipe work accounts from jailbroken/rooted phones automatically πŸ‘.

      No IT config needed. πŸ”₯

      3-phase rollout starting Feb 2026:
      ⚠️ Warn β†’ 🚫 Block β†’ πŸ—‘οΈ Wipe

      Let your help desk and security teams know.

      πŸ”— https://support.microsoft.com/en-us/account-billing/jailbreak-root-detection-in-microsoft-authenticator-9f0431bd-675a-4f2d-b8fb-7acd18deaadc

      Link Preview Image
      pq1r@tech.lgbtP This user is from outside of this forum
      pq1r@tech.lgbtP This user is from outside of this forum
      pq1r@tech.lgbt
      wrote last edited by
      #16

      @merill this idiocy looks like something @GrapheneOS will want to respond to. Microsoft doesn't care if the OS has the latest patches, only that it was certified by the duopoly.

      adambyte@dragonscave.spaceA 1 Reply Last reply
      0
      • agowa338@chaos.socialA agowa338@chaos.social

        @xssfox @merill

        Ehm, the azure codes are a bit different than the TOTP ones. Their app also has a kinda proprietary auth code format too. I think it is mainly about them. As for all others you literally just have to store a picture of the QR-Code you used to set them up...

        Edit: But yea, it probably will end in there being a shady cracked version of the Microsoft Authenticator App that continues to work on rooted phones...

        xssfox@cloudisland.nzX This user is from outside of this forum
        xssfox@cloudisland.nzX This user is from outside of this forum
        xssfox@cloudisland.nz
        wrote last edited by
        #17

        @agowa338 @merill sure but you can get the private data which is the core point of this protection

        agowa338@chaos.socialA 1 Reply Last reply
        0
        • xssfox@cloudisland.nzX xssfox@cloudisland.nz

          @agowa338 @merill sure but you can get the private data which is the core point of this protection

          agowa338@chaos.socialA This user is from outside of this forum
          agowa338@chaos.socialA This user is from outside of this forum
          agowa338@chaos.social
          wrote last edited by
          #18

          @xssfox @merill

          Haven't actually looked at how they're doing it. But yea, you can always crack these things.

          All that they're doing by adding root detection is forcing people that can't do this themselves to download a modified version off of some shady backyard Russian forum or something...

          1 Reply Last reply
          0
          • merill@infosec.exchangeM merill@infosec.exchange

            Microsoft Authenticator is about to wipe work accounts from jailbroken/rooted phones automatically πŸ‘.

            No IT config needed. πŸ”₯

            3-phase rollout starting Feb 2026:
            ⚠️ Warn β†’ 🚫 Block β†’ πŸ—‘οΈ Wipe

            Let your help desk and security teams know.

            πŸ”— https://support.microsoft.com/en-us/account-billing/jailbreak-root-detection-in-microsoft-authenticator-9f0431bd-675a-4f2d-b8fb-7acd18deaadc

            Link Preview Image
            czauner@social.vivaldi.netC This user is from outside of this forum
            czauner@social.vivaldi.netC This user is from outside of this forum
            czauner@social.vivaldi.net
            wrote last edited by
            #19

            @merill

            Well another pretty bad idea. You seem to have quite a streak with those, lately.

            Time to stock up with popcorn and wait for the fallout.

            1 Reply Last reply
            0
            • merill@infosec.exchangeM merill@infosec.exchange

              Microsoft Authenticator is about to wipe work accounts from jailbroken/rooted phones automatically πŸ‘.

              No IT config needed. πŸ”₯

              3-phase rollout starting Feb 2026:
              ⚠️ Warn β†’ 🚫 Block β†’ πŸ—‘οΈ Wipe

              Let your help desk and security teams know.

              πŸ”— https://support.microsoft.com/en-us/account-billing/jailbreak-root-detection-in-microsoft-authenticator-9f0431bd-675a-4f2d-b8fb-7acd18deaadc

              Link Preview Image
              krazov@mstdn.socialK This user is from outside of this forum
              krazov@mstdn.socialK This user is from outside of this forum
              krazov@mstdn.social
              wrote last edited by
              #20

              @merill Whoa.

              1 Reply Last reply
              0
              • merill@infosec.exchangeM merill@infosec.exchange

                Microsoft Authenticator is about to wipe work accounts from jailbroken/rooted phones automatically πŸ‘.

                No IT config needed. πŸ”₯

                3-phase rollout starting Feb 2026:
                ⚠️ Warn β†’ 🚫 Block β†’ πŸ—‘οΈ Wipe

                Let your help desk and security teams know.

                πŸ”— https://support.microsoft.com/en-us/account-billing/jailbreak-root-detection-in-microsoft-authenticator-9f0431bd-675a-4f2d-b8fb-7acd18deaadc

                Link Preview Image
                exilsarahl@chaos.socialE This user is from outside of this forum
                exilsarahl@chaos.socialE This user is from outside of this forum
                exilsarahl@chaos.social
                wrote last edited by
                #21

                @merill is this a threat or promise?

                1 Reply Last reply
                0
                • merill@infosec.exchangeM merill@infosec.exchange

                  Microsoft Authenticator is about to wipe work accounts from jailbroken/rooted phones automatically πŸ‘.

                  No IT config needed. πŸ”₯

                  3-phase rollout starting Feb 2026:
                  ⚠️ Warn β†’ 🚫 Block β†’ πŸ—‘οΈ Wipe

                  Let your help desk and security teams know.

                  πŸ”— https://support.microsoft.com/en-us/account-billing/jailbreak-root-detection-in-microsoft-authenticator-9f0431bd-675a-4f2d-b8fb-7acd18deaadc

                  Link Preview Image
                  pa27@mastodon.socialP This user is from outside of this forum
                  pa27@mastodon.socialP This user is from outside of this forum
                  pa27@mastodon.social
                  wrote last edited by
                  #22

                  @merill Who is using MS Auth anyway? Not me for sure! Another reason not to have or use an MS account...

                  1 Reply Last reply
                  0
                  • merill@infosec.exchangeM merill@infosec.exchange

                    Microsoft Authenticator is about to wipe work accounts from jailbroken/rooted phones automatically πŸ‘.

                    No IT config needed. πŸ”₯

                    3-phase rollout starting Feb 2026:
                    ⚠️ Warn β†’ 🚫 Block β†’ πŸ—‘οΈ Wipe

                    Let your help desk and security teams know.

                    πŸ”— https://support.microsoft.com/en-us/account-billing/jailbreak-root-detection-in-microsoft-authenticator-9f0431bd-675a-4f2d-b8fb-7acd18deaadc

                    Link Preview Image
                    merill@infosec.exchangeM This user is from outside of this forum
                    merill@infosec.exchangeM This user is from outside of this forum
                    merill@infosec.exchange
                    wrote last edited by
                    #23

                    Wow. So a LOT of you folks are not happy.

                    The good news is your org can still allow you to use passkeys and other Authenticator apps.

                    clickhere@mastodon.ieC thekilt@infosec.exchangeT Z dodecahedrus@mastodon.socialD nachof@mastodon.uyN 5 Replies Last reply
                    0
                    • fluffykittycat@furry.engineerF fluffykittycat@furry.engineer

                      @merill in other words, devices that the users control, instead of controlled by someone in the Epstein files

                      gbargoud@masto.nycG This user is from outside of this forum
                      gbargoud@masto.nycG This user is from outside of this forum
                      gbargoud@masto.nyc
                      wrote last edited by
                      #24

                      @fluffykittycat @merill

                      You can opt out any time by showing documentation that you are in the files (tangentially mentioned because they cited your work in an email does not count sorry)

                      1 Reply Last reply
                      0
                      • fluffykittycat@furry.engineerF fluffykittycat@furry.engineer

                        @merill in other words, devices that the users control, instead of controlled by someone in the Epstein files

                        thaodan@mastodon.socialT This user is from outside of this forum
                        thaodan@mastodon.socialT This user is from outside of this forum
                        thaodan@mastodon.social
                        wrote last edited by
                        #25

                        @fluffykittycat @merill It's kind of a grey area. They are right that open bootloaders are a security issue but then also you can relock it on some devices.
                        In any case I don't think I would use the Microsoft Authentication app anyway unless I have to.

                        crazyeddie@mastodon.socialC 1 Reply Last reply
                        0
                        • merill@infosec.exchangeM merill@infosec.exchange

                          Microsoft Authenticator is about to wipe work accounts from jailbroken/rooted phones automatically πŸ‘.

                          No IT config needed. πŸ”₯

                          3-phase rollout starting Feb 2026:
                          ⚠️ Warn β†’ 🚫 Block β†’ πŸ—‘οΈ Wipe

                          Let your help desk and security teams know.

                          πŸ”— https://support.microsoft.com/en-us/account-billing/jailbreak-root-detection-in-microsoft-authenticator-9f0431bd-675a-4f2d-b8fb-7acd18deaadc

                          Link Preview Image
                          H This user is from outside of this forum
                          H This user is from outside of this forum
                          harrymutt@social.vivaldi.net
                          wrote last edited by
                          #26

                          @merill

                          Hmm, I would never in my life install any M$ crap on my /e/OS ungoogled Fairphone. It's not rooted, but I guess it's also among the undesirables...

                          For authentication to our goddamn work accounts on M$, I use AEGIS. Or the standard authenticator on Linux Mint. Export/Import between the two works like a charm.

                          And it could well be that we are moving away from microslob in the not so far future. Unthinkable not so long ago. Halleluja!

                          1 Reply Last reply
                          0
                          • merill@infosec.exchangeM merill@infosec.exchange

                            Microsoft Authenticator is about to wipe work accounts from jailbroken/rooted phones automatically πŸ‘.

                            No IT config needed. πŸ”₯

                            3-phase rollout starting Feb 2026:
                            ⚠️ Warn β†’ 🚫 Block β†’ πŸ—‘οΈ Wipe

                            Let your help desk and security teams know.

                            πŸ”— https://support.microsoft.com/en-us/account-billing/jailbreak-root-detection-in-microsoft-authenticator-9f0431bd-675a-4f2d-b8fb-7acd18deaadc

                            Link Preview Image
                            barubary@infosec.exchangeB This user is from outside of this forum
                            barubary@infosec.exchangeB This user is from outside of this forum
                            barubary@infosec.exchange
                            wrote last edited by
                            #27

                            @merill Thank you for sabotaging my devices.

                            1 Reply Last reply
                            0
                            • merill@infosec.exchangeM merill@infosec.exchange

                              Microsoft Authenticator is about to wipe work accounts from jailbroken/rooted phones automatically πŸ‘.

                              No IT config needed. πŸ”₯

                              3-phase rollout starting Feb 2026:
                              ⚠️ Warn β†’ 🚫 Block β†’ πŸ—‘οΈ Wipe

                              Let your help desk and security teams know.

                              πŸ”— https://support.microsoft.com/en-us/account-billing/jailbreak-root-detection-in-microsoft-authenticator-9f0431bd-675a-4f2d-b8fb-7acd18deaadc

                              Link Preview Image
                              silhouette@dumbfuckingweb.siteS This user is from outside of this forum
                              silhouette@dumbfuckingweb.siteS This user is from outside of this forum
                              silhouette@dumbfuckingweb.site
                              wrote last edited by
                              #28

                              @merill I'm gonna go out on a limb here and say that users that jailbreak their own private device wouldn't use MS Authenticator, and on company devices jailbreak wasn't allowed anyway.

                              fluffykittycat@furry.engineerF 1 Reply Last reply
                              0
                              • merill@infosec.exchangeM merill@infosec.exchange

                                Microsoft Authenticator is about to wipe work accounts from jailbroken/rooted phones automatically πŸ‘.

                                No IT config needed. πŸ”₯

                                3-phase rollout starting Feb 2026:
                                ⚠️ Warn β†’ 🚫 Block β†’ πŸ—‘οΈ Wipe

                                Let your help desk and security teams know.

                                πŸ”— https://support.microsoft.com/en-us/account-billing/jailbreak-root-detection-in-microsoft-authenticator-9f0431bd-675a-4f2d-b8fb-7acd18deaadc

                                Link Preview Image
                                the_wub@mastodon.socialT This user is from outside of this forum
                                the_wub@mastodon.socialT This user is from outside of this forum
                                the_wub@mastodon.social
                                wrote last edited by
                                #29

                                @merill Blanket bans of any sort implemented by large and powerful companies always produce false positives that hurt non-customer that have to interact with their systems no matter how obliquely.

                                I do not use any Microsoft product or services directly but I am sure I will discover ways that this change will affect me. Likely at a moment I need to do something urgently.

                                Never forget Scunthorpe!

                                Link Preview Image
                                Scunthorpe problem - Wikipedia

                                favicon

                                (en.wikipedia.org)

                                1 Reply Last reply
                                0
                                • merill@infosec.exchangeM merill@infosec.exchange

                                  Microsoft Authenticator is about to wipe work accounts from jailbroken/rooted phones automatically πŸ‘.

                                  No IT config needed. πŸ”₯

                                  3-phase rollout starting Feb 2026:
                                  ⚠️ Warn β†’ 🚫 Block β†’ πŸ—‘οΈ Wipe

                                  Let your help desk and security teams know.

                                  πŸ”— https://support.microsoft.com/en-us/account-billing/jailbreak-root-detection-in-microsoft-authenticator-9f0431bd-675a-4f2d-b8fb-7acd18deaadc

                                  Link Preview Image
                                  aetios@sns.minovsky.spaceA This user is from outside of this forum
                                  aetios@sns.minovsky.spaceA This user is from outside of this forum
                                  aetios@sns.minovsky.space
                                  wrote last edited by
                                  #30
                                  @merill wow cringe
                                  1 Reply Last reply
                                  0
                                  • merill@infosec.exchangeM merill@infosec.exchange

                                    Microsoft Authenticator is about to wipe work accounts from jailbroken/rooted phones automatically πŸ‘.

                                    No IT config needed. πŸ”₯

                                    3-phase rollout starting Feb 2026:
                                    ⚠️ Warn β†’ 🚫 Block β†’ πŸ—‘οΈ Wipe

                                    Let your help desk and security teams know.

                                    πŸ”— https://support.microsoft.com/en-us/account-billing/jailbreak-root-detection-in-microsoft-authenticator-9f0431bd-675a-4f2d-b8fb-7acd18deaadc

                                    Link Preview Image
                                    jtig@infosec.exchangeJ This user is from outside of this forum
                                    jtig@infosec.exchangeJ This user is from outside of this forum
                                    jtig@infosec.exchange
                                    wrote last edited by
                                    #31

                                    @merill people making a mountain from a molehill? On Mastodon? Never expected it…

                                    Yes, it’s shitty. But:

                                    • You can do non-Authenticator passkeys now, from other apps that you can use on non-Android devices
                                    • If device-bound, Authenticator native passkeys are forced on your work device, you did not had a say in the matter already.
                                    • If device-bound passkeys are mandated on your personal device, reject the use of work apps on your personal devices and get a security key instead!
                                    1 Reply Last reply
                                    0
                                    • merill@infosec.exchangeM merill@infosec.exchange

                                      Microsoft Authenticator is about to wipe work accounts from jailbroken/rooted phones automatically πŸ‘.

                                      No IT config needed. πŸ”₯

                                      3-phase rollout starting Feb 2026:
                                      ⚠️ Warn β†’ 🚫 Block β†’ πŸ—‘οΈ Wipe

                                      Let your help desk and security teams know.

                                      πŸ”— https://support.microsoft.com/en-us/account-billing/jailbreak-root-detection-in-microsoft-authenticator-9f0431bd-675a-4f2d-b8fb-7acd18deaadc

                                      Link Preview Image
                                      ralph@hear-me.socialR This user is from outside of this forum
                                      ralph@hear-me.socialR This user is from outside of this forum
                                      ralph@hear-me.social
                                      wrote last edited by
                                      #32

                                      @merill

                                      #alttext

                                      Jailbreak/root detection in Microsoft Authenticator.
                                      Between Feb to Jul 2026, Microsoft will introduce jailbreak/root detection in Microsoft Authenticator. Rollout will occur in three phases, and complete in July 2026.

                                      Warn mode:
                                      Your device is rooted.
                                      You'll eventually be unable to add or use your work or school accounts on this device.
                                      This device has been modified to bypass built-in security protections. You can no longer add or use a work or school account on this device
                                      Contact your organization's support team for help.

                                      Block mode:
                                      Your device is rooted.
                                      You can no longer add or use a work or school account on this device.
                                      This device has been modified to bypass built-in security protections. You can no longer add or use a work or school account on this device.
                                      Contact your organization's support team for help.

                                      Wipe mode:
                                      Your device is rooted.
                                      You can no longer add or use a work or school account on this device.
                                      This device has been modified to bypass built-in security protections.
                                      Your work or school accounts have been removed from this device to protect your organization's data. Contact your organization's support team for help.

                                      1 Reply Last reply
                                      0
                                      • merill@infosec.exchangeM merill@infosec.exchange

                                        Microsoft Authenticator is about to wipe work accounts from jailbroken/rooted phones automatically πŸ‘.

                                        No IT config needed. πŸ”₯

                                        3-phase rollout starting Feb 2026:
                                        ⚠️ Warn β†’ 🚫 Block β†’ πŸ—‘οΈ Wipe

                                        Let your help desk and security teams know.

                                        πŸ”— https://support.microsoft.com/en-us/account-billing/jailbreak-root-detection-in-microsoft-authenticator-9f0431bd-675a-4f2d-b8fb-7acd18deaadc

                                        Link Preview Image
                                        longplay_games@mastodon.gamedev.placeL This user is from outside of this forum
                                        longplay_games@mastodon.gamedev.placeL This user is from outside of this forum
                                        longplay_games@mastodon.gamedev.place
                                        wrote last edited by
                                        #33

                                        @merill TIL people actually use the MS authenticator

                                        fluffykittycat@furry.engineerF 1 Reply Last reply
                                        0
                                        • merill@infosec.exchangeM merill@infosec.exchange

                                          Wow. So a LOT of you folks are not happy.

                                          The good news is your org can still allow you to use passkeys and other Authenticator apps.

                                          clickhere@mastodon.ieC This user is from outside of this forum
                                          clickhere@mastodon.ieC This user is from outside of this forum
                                          clickhere@mastodon.ie
                                          wrote last edited by
                                          #34

                                          @merill lol!

                                          Link Preview Image
                                          1 Reply Last reply
                                          0
                                          • R relay@relay.an.exchange shared this topic
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups