News: 1608144314

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Log right in, the water's fine, whispers Microsoft as it adds autofill to Authenticator app

(2020/12/16)


Microsoft has [1]opened up the public preview of password autofill via its Authenticator app for iOS and Android.

Requiring iOS 12.0 or above, or Android 6.0 and later, [2]Microsoft's Authenticator app (initially aimed at two-factor authentication) has been pressed into password management.

Entering a crowded market already populated by the likes of LastPass and Apple's own version, the app will autofill strong passwords on devices and stash the data in the user's Microsoft account. The usernames and passwords are then available across devices using the same account, including the desktop via Edge and an extension for Google Chrome.

It's an interesting move by Microsoft, a company that has been trying to urge users to go [3]passwordless [registration required] and [4]adopt alternatives , such as multi-factor authentication.

However, recognising the reality of the world ("we understand many sites still require passwords and some don't even support multi-factor authentication") it has tweaked things in Authenticator to make it a handy password generator and autofill tool.

For those who don't already have a password manager with mobile app in place, the beta (and this is very much a preview at present) works pretty seamlessly. Once the option has been enabled in the settings of the app, it's a simple matter of pointing the autofill option of the host OS to the app in order to kick things off.

There are some downsides besides the need to be in Microsoft's world to make it work. There doesn't seem to be an option to import usernames and passwords from third parties and it is disabled for enterprise users who are using the app for phone sign-in or multi-factor authentication. There are some options for IT admins determined to bring the functionality to their users, but it's a bit all-or-nothing at an enterprise level at the moment and lacks granular control.

The update is rolling out now. ®

Get our [5]Tech Resources



[1] https://techcommunity.microsoft.com/t5/azure-active-directory-identity/securely-manage-and-autofill-passwords-across-all-your-mobile/ba-p/1751710

[2] https://docs.microsoft.com/en-gb/azure/active-directory/user-help/user-help-auth-app-overview

[3] https://whitepapers.theregister.com/paper/view/10032/passwordless-authentication-how-giving-up-your-password-might-make-you-more-secure

[4] https://www.theregister.com/2018/11/21/fido2/

[5] https://whitepapers.theregister.com/

IceC0ld

not sure here, on the one hand there ARE alot of sites that still only have a paassword access, so yes, it is hitting a need, but maybe it would have been better to try and educate the masses ........................

WTF am I saying, educate the masses, they are the reason most of us have jobs ffs

so maybe MS got it right, but as to whether I will use it, again, let us wait and see what the early adopter brigade say ?

What's the point of MFA now ?

DevOpsTimothyC

So the whole point of MFA is that all the credentials are in a single location.

Next someone will be telling me that their authentication app is built on IE technology and not to worry because there are no "known" unpatched vulnerabilities

John the Baptist after poisoning a thief,
Looks up at his hero, the Commander-in-Chief,
Saying tell me great leader, but please make it brief
Is there a hole for me to get sick in?
The Commander-in-Chief answers him while chasing a fly,
Saying death to all those who would whimper and cry.
And dropping a barbell he points to the sky,
Saying the sun is not yellow, it's chicken.
-- Bob Dylan, "Tombstone Blues"