Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Microsoft Authenticator is about to wipe work accounts from jailbroken/rooted phones automatically πŸ‘.

Microsoft Authenticator is about to wipe work accounts from jailbroken/rooted phones automatically πŸ‘.

Scheduled Pinned Locked Moved Uncategorized
66 Posts 44 Posters 137 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • domi@donotsta.reD domi@donotsta.re

    @merill@infosec.exchange cringe

    amy@sk.girlthi.ngA This user is from outside of this forum
    amy@sk.girlthi.ngA This user is from outside of this forum
    amy@sk.girlthi.ng
    wrote last edited by
    #7

    @domi@donotsta.re @merill@infosec.exchange good guy microsoft protecting us from big scary threats whilst locking token protection (the primary defence to phishing your creds out) behind expensive entra licenses. be so fuckin fr

    domi@donotsta.reD 1 Reply Last reply
    0
    • merill@infosec.exchangeM merill@infosec.exchange

      Microsoft Authenticator is about to wipe work accounts from jailbroken/rooted phones automatically πŸ‘.

      No IT config needed. πŸ”₯

      3-phase rollout starting Feb 2026:
      ⚠️ Warn β†’ 🚫 Block β†’ πŸ—‘οΈ Wipe

      Let your help desk and security teams know.

      πŸ”— https://support.microsoft.com/en-us/account-billing/jailbreak-root-detection-in-microsoft-authenticator-9f0431bd-675a-4f2d-b8fb-7acd18deaadc

      bernardsheppard@mastodon.auB This user is from outside of this forum
      bernardsheppard@mastodon.auB This user is from outside of this forum
      bernardsheppard@mastodon.au
      wrote last edited by
      #8

      @merill magisk module to hide root incoming in 3, 2, 1...

      kuniti_shino@pounced-on.meK 1 Reply Last reply
      0
      • amy@sk.girlthi.ngA amy@sk.girlthi.ng

        @domi@donotsta.re @merill@infosec.exchange good guy microsoft protecting us from big scary threats whilst locking token protection (the primary defence to phishing your creds out) behind expensive entra licenses. be so fuckin fr

        domi@donotsta.reD This user is from outside of this forum
        domi@donotsta.reD This user is from outside of this forum
        domi@donotsta.re
        wrote last edited by
        #9

        @amy@sk.girlthi.ng @merill@infosec.exchange microslop will save us all!

        (they can't censor me here :^)

        kuriko@wetdry.worldK 1 Reply Last reply
        0
        • domi@donotsta.reD domi@donotsta.re

          @amy@sk.girlthi.ng @merill@infosec.exchange microslop will save us all!

          (they can't censor me here :^)

          kuriko@wetdry.worldK This user is from outside of this forum
          kuriko@wetdry.worldK This user is from outside of this forum
          kuriko@wetdry.world
          wrote last edited by
          #10

          @domi @amy
          @microsoft get them

          amy@sk.girlthi.ngA 1 Reply Last reply
          0
          • kuriko@wetdry.worldK kuriko@wetdry.world

            @domi @amy
            @microsoft get them

            amy@sk.girlthi.ngA This user is from outside of this forum
            amy@sk.girlthi.ngA This user is from outside of this forum
            amy@sk.girlthi.ng
            wrote last edited by
            #11

            @kuriko@wetdry.world @domi@donotsta.re @microsoft@lea.pet OH GOD OH FUCKK

            1 Reply Last reply
            0
            • lnr@sunny.gardenL lnr@sunny.garden

              @merill I have to admit one of the reasons I use the web application for Outlook on my phone is because installing the Outlook app and adding my work account to it would in theory give work access to control (parts of) my phone - which I don't want. I didn't think the authenticator alone would give that level of access to the device though!

              Is this likely to just drive more people to switch to using Google's authenticator (or another TOTP app) instead of the Microsoft one? I do anyway, because I was already using it for other sites, and it was easier to have them all in one place. You'd lose push authentications: but I feel safer without those anyway!

              resuna@ohai.socialR This user is from outside of this forum
              resuna@ohai.socialR This user is from outside of this forum
              resuna@ohai.social
              wrote last edited by
              #12

              @lnr @merill

              When I worked at Halliburton I asked if there was any way to get email on my phone, and they said they didn't even support BYOD because having someone's phone locked out because it was being wiped right when they'd just been laid off was too evil for them.

              1 Reply Last reply
              0
              • agowa338@chaos.socialA agowa338@chaos.social

                @merill

                Soo instead of just rooting a phone one needs now to also deploy 38473894 shady scripts and workarounds to hide it from Microsoft Authenticator?

                Congratulation on improving security (NOT).

                xssfox@cloudisland.nzX This user is from outside of this forum
                xssfox@cloudisland.nzX This user is from outside of this forum
                xssfox@cloudisland.nz
                wrote last edited by
                #13

                @agowa338 @merill and someone attacking will still be able to grab the codes before being wiped because you just stop the app before dumping the data

                agowa338@chaos.socialA 1 Reply Last reply
                0
                • merill@infosec.exchangeM merill@infosec.exchange

                  Microsoft Authenticator is about to wipe work accounts from jailbroken/rooted phones automatically πŸ‘.

                  No IT config needed. πŸ”₯

                  3-phase rollout starting Feb 2026:
                  ⚠️ Warn β†’ 🚫 Block β†’ πŸ—‘οΈ Wipe

                  Let your help desk and security teams know.

                  πŸ”— https://support.microsoft.com/en-us/account-billing/jailbreak-root-detection-in-microsoft-authenticator-9f0431bd-675a-4f2d-b8fb-7acd18deaadc

                  Z This user is from outside of this forum
                  Z This user is from outside of this forum
                  zsapi@mastodon.social
                  wrote last edited by
                  #14

                  @merill yeah sure, make sure we can't control our devices as we want to, but only as the duopoly/governments allow. Great step toward freedom and security /s

                  1 Reply Last reply
                  0
                  • xssfox@cloudisland.nzX xssfox@cloudisland.nz

                    @agowa338 @merill and someone attacking will still be able to grab the codes before being wiped because you just stop the app before dumping the data

                    agowa338@chaos.socialA This user is from outside of this forum
                    agowa338@chaos.socialA This user is from outside of this forum
                    agowa338@chaos.social
                    wrote last edited by
                    #15

                    @xssfox @merill

                    Ehm, the azure codes are a bit different than the TOTP ones. Their app also has a kinda proprietary auth code format too. I think it is mainly about them. As for all others you literally just have to store a picture of the QR-Code you used to set them up...

                    Edit: But yea, it probably will end in there being a shady cracked version of the Microsoft Authenticator App that continues to work on rooted phones...

                    xssfox@cloudisland.nzX 1 Reply Last reply
                    0
                    • merill@infosec.exchangeM merill@infosec.exchange

                      Microsoft Authenticator is about to wipe work accounts from jailbroken/rooted phones automatically πŸ‘.

                      No IT config needed. πŸ”₯

                      3-phase rollout starting Feb 2026:
                      ⚠️ Warn β†’ 🚫 Block β†’ πŸ—‘οΈ Wipe

                      Let your help desk and security teams know.

                      πŸ”— https://support.microsoft.com/en-us/account-billing/jailbreak-root-detection-in-microsoft-authenticator-9f0431bd-675a-4f2d-b8fb-7acd18deaadc

                      pq1r@tech.lgbtP This user is from outside of this forum
                      pq1r@tech.lgbtP This user is from outside of this forum
                      pq1r@tech.lgbt
                      wrote last edited by
                      #16

                      @merill this idiocy looks like something @GrapheneOS will want to respond to. Microsoft doesn't care if the OS has the latest patches, only that it was certified by the duopoly.

                      adambyte@dragonscave.spaceA 1 Reply Last reply
                      0
                      • agowa338@chaos.socialA agowa338@chaos.social

                        @xssfox @merill

                        Ehm, the azure codes are a bit different than the TOTP ones. Their app also has a kinda proprietary auth code format too. I think it is mainly about them. As for all others you literally just have to store a picture of the QR-Code you used to set them up...

                        Edit: But yea, it probably will end in there being a shady cracked version of the Microsoft Authenticator App that continues to work on rooted phones...

                        xssfox@cloudisland.nzX This user is from outside of this forum
                        xssfox@cloudisland.nzX This user is from outside of this forum
                        xssfox@cloudisland.nz
                        wrote last edited by
                        #17

                        @agowa338 @merill sure but you can get the private data which is the core point of this protection

                        agowa338@chaos.socialA 1 Reply Last reply
                        0
                        • xssfox@cloudisland.nzX xssfox@cloudisland.nz

                          @agowa338 @merill sure but you can get the private data which is the core point of this protection

                          agowa338@chaos.socialA This user is from outside of this forum
                          agowa338@chaos.socialA This user is from outside of this forum
                          agowa338@chaos.social
                          wrote last edited by
                          #18

                          @xssfox @merill

                          Haven't actually looked at how they're doing it. But yea, you can always crack these things.

                          All that they're doing by adding root detection is forcing people that can't do this themselves to download a modified version off of some shady backyard Russian forum or something...

                          1 Reply Last reply
                          0
                          • merill@infosec.exchangeM merill@infosec.exchange

                            Microsoft Authenticator is about to wipe work accounts from jailbroken/rooted phones automatically πŸ‘.

                            No IT config needed. πŸ”₯

                            3-phase rollout starting Feb 2026:
                            ⚠️ Warn β†’ 🚫 Block β†’ πŸ—‘οΈ Wipe

                            Let your help desk and security teams know.

                            πŸ”— https://support.microsoft.com/en-us/account-billing/jailbreak-root-detection-in-microsoft-authenticator-9f0431bd-675a-4f2d-b8fb-7acd18deaadc

                            czauner@social.vivaldi.netC This user is from outside of this forum
                            czauner@social.vivaldi.netC This user is from outside of this forum
                            czauner@social.vivaldi.net
                            wrote last edited by
                            #19

                            @merill

                            Well another pretty bad idea. You seem to have quite a streak with those, lately.

                            Time to stock up with popcorn and wait for the fallout.

                            1 Reply Last reply
                            0
                            • merill@infosec.exchangeM merill@infosec.exchange

                              Microsoft Authenticator is about to wipe work accounts from jailbroken/rooted phones automatically πŸ‘.

                              No IT config needed. πŸ”₯

                              3-phase rollout starting Feb 2026:
                              ⚠️ Warn β†’ 🚫 Block β†’ πŸ—‘οΈ Wipe

                              Let your help desk and security teams know.

                              πŸ”— https://support.microsoft.com/en-us/account-billing/jailbreak-root-detection-in-microsoft-authenticator-9f0431bd-675a-4f2d-b8fb-7acd18deaadc

                              krazov@mstdn.socialK This user is from outside of this forum
                              krazov@mstdn.socialK This user is from outside of this forum
                              krazov@mstdn.social
                              wrote last edited by
                              #20

                              @merill Whoa.

                              1 Reply Last reply
                              0
                              • merill@infosec.exchangeM merill@infosec.exchange

                                Microsoft Authenticator is about to wipe work accounts from jailbroken/rooted phones automatically πŸ‘.

                                No IT config needed. πŸ”₯

                                3-phase rollout starting Feb 2026:
                                ⚠️ Warn β†’ 🚫 Block β†’ πŸ—‘οΈ Wipe

                                Let your help desk and security teams know.

                                πŸ”— https://support.microsoft.com/en-us/account-billing/jailbreak-root-detection-in-microsoft-authenticator-9f0431bd-675a-4f2d-b8fb-7acd18deaadc

                                exilsarahl@chaos.socialE This user is from outside of this forum
                                exilsarahl@chaos.socialE This user is from outside of this forum
                                exilsarahl@chaos.social
                                wrote last edited by
                                #21

                                @merill is this a threat or promise?

                                1 Reply Last reply
                                0
                                • merill@infosec.exchangeM merill@infosec.exchange

                                  Microsoft Authenticator is about to wipe work accounts from jailbroken/rooted phones automatically πŸ‘.

                                  No IT config needed. πŸ”₯

                                  3-phase rollout starting Feb 2026:
                                  ⚠️ Warn β†’ 🚫 Block β†’ πŸ—‘οΈ Wipe

                                  Let your help desk and security teams know.

                                  πŸ”— https://support.microsoft.com/en-us/account-billing/jailbreak-root-detection-in-microsoft-authenticator-9f0431bd-675a-4f2d-b8fb-7acd18deaadc

                                  pa27@mastodon.socialP This user is from outside of this forum
                                  pa27@mastodon.socialP This user is from outside of this forum
                                  pa27@mastodon.social
                                  wrote last edited by
                                  #22

                                  @merill Who is using MS Auth anyway? Not me for sure! Another reason not to have or use an MS account...

                                  1 Reply Last reply
                                  0
                                  • merill@infosec.exchangeM merill@infosec.exchange

                                    Microsoft Authenticator is about to wipe work accounts from jailbroken/rooted phones automatically πŸ‘.

                                    No IT config needed. πŸ”₯

                                    3-phase rollout starting Feb 2026:
                                    ⚠️ Warn β†’ 🚫 Block β†’ πŸ—‘οΈ Wipe

                                    Let your help desk and security teams know.

                                    πŸ”— https://support.microsoft.com/en-us/account-billing/jailbreak-root-detection-in-microsoft-authenticator-9f0431bd-675a-4f2d-b8fb-7acd18deaadc

                                    merill@infosec.exchangeM This user is from outside of this forum
                                    merill@infosec.exchangeM This user is from outside of this forum
                                    merill@infosec.exchange
                                    wrote last edited by
                                    #23

                                    Wow. So a LOT of you folks are not happy.

                                    The good news is your org can still allow you to use passkeys and other Authenticator apps.

                                    clickhere@mastodon.ieC thekilt@infosec.exchangeT Z dodecahedrus@mastodon.socialD nachof@mastodon.uyN 5 Replies Last reply
                                    0
                                    • fluffykittycat@furry.engineerF fluffykittycat@furry.engineer

                                      @merill in other words, devices that the users control, instead of controlled by someone in the Epstein files

                                      gbargoud@masto.nycG This user is from outside of this forum
                                      gbargoud@masto.nycG This user is from outside of this forum
                                      gbargoud@masto.nyc
                                      wrote last edited by
                                      #24

                                      @fluffykittycat @merill

                                      You can opt out any time by showing documentation that you are in the files (tangentially mentioned because they cited your work in an email does not count sorry)

                                      1 Reply Last reply
                                      0
                                      • fluffykittycat@furry.engineerF fluffykittycat@furry.engineer

                                        @merill in other words, devices that the users control, instead of controlled by someone in the Epstein files

                                        thaodan@mastodon.socialT This user is from outside of this forum
                                        thaodan@mastodon.socialT This user is from outside of this forum
                                        thaodan@mastodon.social
                                        wrote last edited by
                                        #25

                                        @fluffykittycat @merill It's kind of a grey area. They are right that open bootloaders are a security issue but then also you can relock it on some devices.
                                        In any case I don't think I would use the Microsoft Authentication app anyway unless I have to.

                                        crazyeddie@mastodon.socialC 1 Reply Last reply
                                        0
                                        • merill@infosec.exchangeM merill@infosec.exchange

                                          Microsoft Authenticator is about to wipe work accounts from jailbroken/rooted phones automatically πŸ‘.

                                          No IT config needed. πŸ”₯

                                          3-phase rollout starting Feb 2026:
                                          ⚠️ Warn β†’ 🚫 Block β†’ πŸ—‘οΈ Wipe

                                          Let your help desk and security teams know.

                                          πŸ”— https://support.microsoft.com/en-us/account-billing/jailbreak-root-detection-in-microsoft-authenticator-9f0431bd-675a-4f2d-b8fb-7acd18deaadc

                                          H This user is from outside of this forum
                                          H This user is from outside of this forum
                                          harrymutt@social.vivaldi.net
                                          wrote last edited by
                                          #26

                                          @merill

                                          Hmm, I would never in my life install any M$ crap on my /e/OS ungoogled Fairphone. It's not rooted, but I guess it's also among the undesirables...

                                          For authentication to our goddamn work accounts on M$, I use AEGIS. Or the standard authenticator on Linux Mint. Export/Import between the two works like a charm.

                                          And it could well be that we are moving away from microslob in the not so far future. Unthinkable not so long ago. Halleluja!

                                          1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups