Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Microsoft Authenticator is about to wipe work accounts from jailbroken/rooted phones automatically πŸ‘.

Microsoft Authenticator is about to wipe work accounts from jailbroken/rooted phones automatically πŸ‘.

Scheduled Pinned Locked Moved Uncategorized
66 Posts 44 Posters 137 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • silhouette@dumbfuckingweb.siteS silhouette@dumbfuckingweb.site

    @merill I'm gonna go out on a limb here and say that users that jailbreak their own private device wouldn't use MS Authenticator, and on company devices jailbreak wasn't allowed anyway.

    fluffykittycat@furry.engineerF This user is from outside of this forum
    fluffykittycat@furry.engineerF This user is from outside of this forum
    fluffykittycat@furry.engineer
    wrote last edited by
    #47

    @silhouette @merill people are expected to put this on their personal devices

    silhouette@dumbfuckingweb.siteS 1 Reply Last reply
    0
    • longplay_games@mastodon.gamedev.placeL longplay_games@mastodon.gamedev.place

      @merill TIL people actually use the MS authenticator

      fluffykittycat@furry.engineerF This user is from outside of this forum
      fluffykittycat@furry.engineerF This user is from outside of this forum
      fluffykittycat@furry.engineer
      wrote last edited by
      #48

      @Longplay_Games @merill not by choice

      1 Reply Last reply
      0
      • fluffykittycat@furry.engineerF fluffykittycat@furry.engineer

        @silhouette @merill people are expected to put this on their personal devices

        silhouette@dumbfuckingweb.siteS This user is from outside of this forum
        silhouette@dumbfuckingweb.siteS This user is from outside of this forum
        silhouette@dumbfuckingweb.site
        wrote last edited by
        #49

        @fluffykittycat @merill ah, the famous "use your own private resources for the benefit of the company".

        xarvos@outerheaven.clubX 1 Reply Last reply
        0
        • fluffykittycat@furry.engineerF fluffykittycat@furry.engineer

          @crazyeddie @thaodan @merill unlocked bootloaders are a moral imperitive. Not to mention all the ewaste created by locked devices not being repurporsable

          thaodan@mastodon.socialT This user is from outside of this forum
          thaodan@mastodon.socialT This user is from outside of this forum
          thaodan@mastodon.social
          wrote last edited by
          #50

          @fluffykittycat @merill @crazyeddie Context? Nobody in the thread said that devices where users can't unlock bootloaders are a good thing.
          Users should just be able to relock it. Locking bootloaders doesn't block flashing it just ensures that only code signing with the owner of the keys in the bootloader can be used, the owner of these keys can be the user.

          crazyeddie@mastodon.socialC 1 Reply Last reply
          0
          • thaodan@mastodon.socialT thaodan@mastodon.social

            @fluffykittycat @merill @crazyeddie Context? Nobody in the thread said that devices where users can't unlock bootloaders are a good thing.
            Users should just be able to relock it. Locking bootloaders doesn't block flashing it just ensures that only code signing with the owner of the keys in the bootloader can be used, the owner of these keys can be the user.

            crazyeddie@mastodon.socialC This user is from outside of this forum
            crazyeddie@mastodon.socialC This user is from outside of this forum
            crazyeddie@mastodon.social
            wrote last edited by
            #51

            @thaodan @fluffykittycat @merill Yeah, I can't re-lock my phone or I believe even put the bootloader into write-only. Sucks.

            fluffykittycat@furry.engineerF 1 Reply Last reply
            0
            • merill@infosec.exchangeM merill@infosec.exchange

              Microsoft Authenticator is about to wipe work accounts from jailbroken/rooted phones automatically πŸ‘.

              No IT config needed. πŸ”₯

              3-phase rollout starting Feb 2026:
              ⚠️ Warn β†’ 🚫 Block β†’ πŸ—‘οΈ Wipe

              Let your help desk and security teams know.

              πŸ”— https://support.microsoft.com/en-us/account-billing/jailbreak-root-detection-in-microsoft-authenticator-9f0431bd-675a-4f2d-b8fb-7acd18deaadc

              renard@equestria.socialR This user is from outside of this forum
              renard@equestria.socialR This user is from outside of this forum
              renard@equestria.social
              wrote last edited by
              #52

              @merill what the fuck. You all really want to kill open computing, don't you.

              1 Reply Last reply
              0
              • crazyeddie@mastodon.socialC crazyeddie@mastodon.social

                @thaodan @fluffykittycat @merill Yeah, I can't re-lock my phone or I believe even put the bootloader into write-only. Sucks.

                fluffykittycat@furry.engineerF This user is from outside of this forum
                fluffykittycat@furry.engineerF This user is from outside of this forum
                fluffykittycat@furry.engineer
                wrote last edited by
                #53

                @crazyeddie @thaodan @merill yeah, locked bootloaders imply the person who purchased it doesn't get full ownership rights over it

                thaodan@mastodon.socialT 1 Reply Last reply
                0
                • bernardsheppard@mastodon.auB bernardsheppard@mastodon.au

                  @merill magisk module to hide root incoming in 3, 2, 1...

                  kuniti_shino@pounced-on.meK This user is from outside of this forum
                  kuniti_shino@pounced-on.meK This user is from outside of this forum
                  kuniti_shino@pounced-on.me
                  wrote last edited by
                  #54

                  @BernardSheppard @merill it exists
                  Just not for android 16

                  bernardsheppard@mastodon.auB 1 Reply Last reply
                  0
                  • merill@infosec.exchangeM merill@infosec.exchange

                    Wow. So a LOT of you folks are not happy.

                    The good news is your org can still allow you to use passkeys and other Authenticator apps.

                    nachof@mastodon.uyN This user is from outside of this forum
                    nachof@mastodon.uyN This user is from outside of this forum
                    nachof@mastodon.uy
                    wrote last edited by
                    #55

                    @merill
                    Wait you were actually saying it as a good thing????

                    1 Reply Last reply
                    0
                    • fluffykittycat@furry.engineerF fluffykittycat@furry.engineer

                      @crazyeddie @thaodan @merill yeah, locked bootloaders imply the person who purchased it doesn't get full ownership rights over it

                      thaodan@mastodon.socialT This user is from outside of this forum
                      thaodan@mastodon.socialT This user is from outside of this forum
                      thaodan@mastodon.social
                      wrote last edited by
                      #56

                      @fluffykittycat @crazyeddie @merill You have to separate the technical from the ideological part. As long as the user has the control for en- and disable the bootloader signature verification they are perfectly fine. There are parts of the device users shouldn't reflash thou such as the radio configuration.

                      fluffykittycat@furry.engineerF 1 Reply Last reply
                      0
                      • kontrollierterwahnwitz@sueden.socialK kontrollierterwahnwitz@sueden.social

                        @merill I wonder who of the people complaining here do…

                        1. … own a rooted / jailbroken phone
                        2. … have Microsoft Authenticator installed on this phone
                        3. … do use MS Authenticator in combination with an Azure Active Directory account.

                        ? Offline
                        ? Offline
                        Guest
                        wrote last edited by
                        #57

                        @kontrollierterWahnwitz@sueden.social anyone meeting criteria 1 who are required to use MS Authenticator for work.

                        1 Reply Last reply
                        0
                        • merill@infosec.exchangeM merill@infosec.exchange

                          Microsoft Authenticator is about to wipe work accounts from jailbroken/rooted phones automatically πŸ‘.

                          No IT config needed. πŸ”₯

                          3-phase rollout starting Feb 2026:
                          ⚠️ Warn β†’ 🚫 Block β†’ πŸ—‘οΈ Wipe

                          Let your help desk and security teams know.

                          πŸ”— https://support.microsoft.com/en-us/account-billing/jailbreak-root-detection-in-microsoft-authenticator-9f0431bd-675a-4f2d-b8fb-7acd18deaadc

                          luana@wetdry.worldL This user is from outside of this forum
                          luana@wetdry.worldL This user is from outside of this forum
                          luana@wetdry.world
                          wrote last edited by
                          #58

                          @merill Yikes.

                          1 Reply Last reply
                          0
                          • thaodan@mastodon.socialT thaodan@mastodon.social

                            @fluffykittycat @crazyeddie @merill You have to separate the technical from the ideological part. As long as the user has the control for en- and disable the bootloader signature verification they are perfectly fine. There are parts of the device users shouldn't reflash thou such as the radio configuration.

                            fluffykittycat@furry.engineerF This user is from outside of this forum
                            fluffykittycat@furry.engineerF This user is from outside of this forum
                            fluffykittycat@furry.engineer
                            wrote last edited by
                            #59

                            @thaodan @crazyeddie @merill why should we expect Microsoft to.honor that? We know they won't

                            1 Reply Last reply
                            0
                            • kuniti_shino@pounced-on.meK kuniti_shino@pounced-on.me

                              @BernardSheppard @merill it exists
                              Just not for android 16

                              bernardsheppard@mastodon.auB This user is from outside of this forum
                              bernardsheppard@mastodon.auB This user is from outside of this forum
                              bernardsheppard@mastodon.au
                              wrote last edited by
                              #60

                              @Kuniti_shino @merill I haven't had need for magisk / shamiko for a while now, but under Android 15, they worked perfectly.

                              Root, recompile to defeat certificate pinning, MITM, hide root and then using something like http toolkit to work out what an application was doing was pretty straightforward.

                              Reverse engineering for everyone.

                              1 Reply Last reply
                              0
                              • silhouette@dumbfuckingweb.siteS silhouette@dumbfuckingweb.site

                                @fluffykittycat @merill ah, the famous "use your own private resources for the benefit of the company".

                                xarvos@outerheaven.clubX This user is from outside of this forum
                                xarvos@outerheaven.clubX This user is from outside of this forum
                                xarvos@outerheaven.club
                                wrote last edited by
                                #61

                                @silhouette@dumbfuckingweb.site @fluffykittycat@furry.engineer @merill@infosec.exchange how else can we call you when you're supposedly sleeping or on vacation?

                                1 Reply Last reply
                                0
                                • merill@infosec.exchangeM merill@infosec.exchange

                                  Microsoft Authenticator is about to wipe work accounts from jailbroken/rooted phones automatically πŸ‘.

                                  No IT config needed. πŸ”₯

                                  3-phase rollout starting Feb 2026:
                                  ⚠️ Warn β†’ 🚫 Block β†’ πŸ—‘οΈ Wipe

                                  Let your help desk and security teams know.

                                  πŸ”— https://support.microsoft.com/en-us/account-billing/jailbreak-root-detection-in-microsoft-authenticator-9f0431bd-675a-4f2d-b8fb-7acd18deaadc

                                  hallunke23@troet.cafeH This user is from outside of this forum
                                  hallunke23@troet.cafeH This user is from outside of this forum
                                  hallunke23@troet.cafe
                                  wrote last edited by
                                  #62

                                  Bloody hell? This looks like fascism to me.

                                  @merill

                                  1 Reply Last reply
                                  0
                                  • kontrollierterwahnwitz@sueden.socialK kontrollierterwahnwitz@sueden.social

                                    @merill I wonder who of the people complaining here do…

                                    1. … own a rooted / jailbroken phone
                                    2. … have Microsoft Authenticator installed on this phone
                                    3. … do use MS Authenticator in combination with an Azure Active Directory account.

                                    drikanis@mstdn.caD This user is from outside of this forum
                                    drikanis@mstdn.caD This user is from outside of this forum
                                    drikanis@mstdn.ca
                                    wrote last edited by
                                    #63

                                    @kontrollierterWahnwitz @merill I'm stuck with Microsoft Authenticator for my work Azure login. I have to use my personal device as they will not issue me one, and no other authenticator option is permitted.

                                    I don't have a rooted device at the moment, but I was planning on rooting it in a couple years when my manufacturer inevitably stops providing updates.

                                    I'm going to ask my work if they can relax the restrictions to allow other authenticators after this change. Otherwise, I'll need to fork up for a new phone out of my own pocket instead of being able to extend the life of my current one.

                                    kontrollierterwahnwitz@sueden.socialK 1 Reply Last reply
                                    0
                                    • pq1r@tech.lgbtP pq1r@tech.lgbt

                                      @merill this idiocy looks like something @GrapheneOS will want to respond to. Microsoft doesn't care if the OS has the latest patches, only that it was certified by the duopoly.

                                      adambyte@dragonscave.spaceA This user is from outside of this forum
                                      adambyte@dragonscave.spaceA This user is from outside of this forum
                                      adambyte@dragonscave.space
                                      wrote last edited by
                                      #64

                                      @pq1r @merill @GrapheneOS GrapheneOS doesn't support rooting, so they don't need to do anything.

                                      1 Reply Last reply
                                      0
                                      • lnr@sunny.gardenL lnr@sunny.garden

                                        @merill I have to admit one of the reasons I use the web application for Outlook on my phone is because installing the Outlook app and adding my work account to it would in theory give work access to control (parts of) my phone - which I don't want. I didn't think the authenticator alone would give that level of access to the device though!

                                        Is this likely to just drive more people to switch to using Google's authenticator (or another TOTP app) instead of the Microsoft one? I do anyway, because I was already using it for other sites, and it was easier to have them all in one place. You'd lose push authentications: but I feel safer without those anyway!

                                        jyrgenn@mas.toJ This user is from outside of this forum
                                        jyrgenn@mas.toJ This user is from outside of this forum
                                        jyrgenn@mas.to
                                        wrote last edited by
                                        #65

                                        @lnr @merill *If* you consider using another TOTP app, I recommend 2FAS Authenticator. Other than the MS and Google authenticators, who are incredibly greedy data harvesters, 2FAS phones home nothing but anonymised diagnostics data. (It does, optionally, sync/backup on Google Drive/iCloud.) Has been working well for me for years. Open source, on Android and iOS.

                                        Link Preview Image
                                        2FAS Auth

                                        Meet your favourite 2FA app. We are an open-source, community-driven, private and simple solution for Internet's biggest threat - security breaches.

                                        favicon

                                        (2fas.com)

                                        Link Preview ImageLink Preview ImageLink Preview Image
                                        1 Reply Last reply
                                        0
                                        • drikanis@mstdn.caD drikanis@mstdn.ca

                                          @kontrollierterWahnwitz @merill I'm stuck with Microsoft Authenticator for my work Azure login. I have to use my personal device as they will not issue me one, and no other authenticator option is permitted.

                                          I don't have a rooted device at the moment, but I was planning on rooting it in a couple years when my manufacturer inevitably stops providing updates.

                                          I'm going to ask my work if they can relax the restrictions to allow other authenticators after this change. Otherwise, I'll need to fork up for a new phone out of my own pocket instead of being able to extend the life of my current one.

                                          kontrollierterwahnwitz@sueden.socialK This user is from outside of this forum
                                          kontrollierterwahnwitz@sueden.socialK This user is from outside of this forum
                                          kontrollierterwahnwitz@sueden.social
                                          wrote last edited by
                                          #66

                                          @drikanis

                                          To be clear: I don't linke the approach MS is doing here and I don't want to blame the people here.

                                          From my understanding, it is your company's job to provide you a device that suits to their environment. For cases like these I have a stock company smartphone without a SIM.

                                          As soon as employers say that you should BYOD, it is not your device anymore. It is the employer's.

                                          @merill

                                          1 Reply Last reply
                                          1
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups