Why would you use microsoft Authenticator anyway? There are other options
post
I can guarantee this will be a hilarious shitstorm of false positives wasting IT departments' time, because their detection of it is massively flawed.
At least once a month my - completely stock, and un-rooted - phone tells me I can't use Outlook/Teams because of root. Every time, a reboot is required to resolve this. One one occasion, TWO reboots.
Ignoring whatever reason Microsoft think they're blocking this for, it's going to regularly block regular users, who are not going to stand for it.
Fuck all these totalitarian corpos.
I don't use my account for email anymore or use Windows very often but I just changed the two factor authenticator to Aegis. They make the text to use an alternative authenticator app tiny blue hyperlink text but you can do it confirmed.
Ths is gonna cause some fun at work. I know our IT team would not be on top of this until one day a portion of employees can't SSO in. Then mayhem will ensue by heels being dug on both sides.
Your company should be issuing devices if employees need to use apps like that. IT issued equipment shouldn't be jailbroken or rooted, it should be managed via MDM.
Otherwise they deserve it for trying to cut corners by having employees use personal devices. If they're doing that, they're almost certainly not paying for the work use of those devices either.
It may be painful but a switch to Ente Auth or similar is a must
verify if your phone is affected
No, i don't use spyware.
Why the fuck would you use a personal phone for work?
Get some cheap alternative and put the authenticator on that phone and say that is your main phone.
2FA is not just for work.
Sure but you can use your own choice of 2FA software for your own stuff
Better yet, if your work requires you to have Microsoft Authenticator, tell them that they need to provide you with a device capable of using it.
Instead of spending your own money on a burner phone just for that, make your work pay for it.
I wont use my personal phone for anything work related except authentication. Since it sits in its own little jail, it's fine.
I work all over the world and remote in. I have no other work related devices or equipment.
I look at it as a key card from the old days when I had to go into a building. I think that is a pretty trivial use case and doesn't need them to provide a phone, and in fact I absolutely would not want a device owned by anyone else that I carried around. That is FAR worse.
That said, this change sucks as I will now need to get around this bullshit.
you don't just use authenticator for work. anybody who plays Minecraft uses it.
There are a couple Android ports of KeePass. They are open source and won't care if your phone is rooted.
Does it even support OTP?
Just use https://github.com/beemdevelopment/Aegis on Android.
How does the tool actually check for this?
Does it just use the Play Integrety API, or does it use some kind of other attestation check?
The need for full root privilege has fallen by the wayside assuming you can trust the OS running on the device. I dont hate this change if I can run a custom ROM that will report that the user does not have root privilege and that the OS has not been modified since boot.
Probably Play Integrity, since it's still working on my phone with the Play Integrity Fix Magisk module installed.
Because, obviously, you can't be a real person if you don't let the corpos control your device.
top 50 comments