Microsoft Authenticator to nuke Entra creds on rooted and jailbroken phones
- Reference: 1773149298
- News link: https://www.theregister.co.uk/2026/03/10/microsoft_authenticator_checks/
- Source link:
The process is automatic and there is no opt-out. If Microsoft Authenticator detects that a device has been jailbroken or rooted, it will first display a warning, then block access, and finally wipe credentials. The [1]procedure is already underway for Android devices, and iOS devices will follow in April 2026.
If all goes to plan, Microsoft will complete the process by July 2026. The app will warn, block, and wipe [2]data "during any interactive operation that involves a work or school account in Microsoft Authenticator."
[3]
There is an argument that an employer should provide employees with suitably locked-down devices anyway, and a jailbroken or rooted device might allow apps to cause all sorts of mischief that could bypass Microsoft's security controls and cause multi-factor authentication (MFA) headaches.
[4]Microsoft 365 confirms new premium tier, stuffed with AI and few discounts
[5]Windows Backup adds second-chance restore at sign-in
[6]Microsoft Azure challenges AWS for downtime crown
[7]Kubernetes kicks down Azure Front Door
However, there are also good reasons to use a device – particularly an Android – that qualifies as jailbroken or rooted. There is plenty of software that only works on devices no longer solely part of a given vendor's ecosystem, although it is important to understand the risks involved.
Microsoft did not detail what checks take place, and other mobile operating systems, such as GrapheneOS, may also face restrictions. Microsoft did not respond to our questions, other than confirming the receipt of The Register's query.
[8]
After receiving the warning, one user [9]remarked : "Disabling the hardened memory allocator for the app got rid of it having an issue with the device."
Microsoft first warned customers last year that the Authocalypse was coming for jailbroken or rooted devices. In response to a post reminding users that the effort was underway, another observer [10]said : "So, the quickest way to clean up tens of M365 accounts that were 'restored' to a new phone (and completely broken) would actually be to root my Pixel?"
[11]
Perhaps not quite what Microsoft had in mind. ®
Get our [12]Tech Resources
[1] https://mc.merill.net/message/MC1179154
[2] https://support.microsoft.com/en-gb/account-billing/jailbreak-root-detection-in-microsoft-authenticator-9f0431bd-675a-4f2d-b8fb-7acd18deaadc
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2abBOOWM06IvAh1Bsa7JROQAAARA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://www.theregister.com/2026/03/09/microsoft_adds_a_premium_tier/
[5] https://www.theregister.com/2026/01/16/microsoft_windows_backup/
[6] https://www.theregister.com/2025/10/29/microsoft_azure_outage/
[7] https://www.theregister.com/2025/10/09/kubernetes_azure_outage/
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44abBOOWM06IvAh1Bsa7JROQAAARA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://www.reddit.com/r/GrapheneOS/comments/1rg48yw/comment/o7oua0j/
[10] https://bsky.app/profile/jukkan.bsky.social/post/3mgooxsmnnc22
[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44abBOOWM06IvAh1Bsa7JROQAAARA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[12] https://whitepapers.theregister.com/
Need a new TOTP then
Recommendations?
Re: Need a new TOTP then
SMS is crApp-free.
Re: Need a new TOTP then
also easy to circumvent with SIM swap/clone
Re: Need a new TOTP then
I'm less worried about my SIM being swapped or cloned than I am the crApp pushers exfiltrating my private data, selling my location, or committing advertising against me.
Re: Need a new TOTP then
Hardware token - Yubikey being the most well known, but there are others.
There is an associated app but all the TOTP seeds are on the token; it has NFC so you can use same TOTP seeds via the phone app.
I started using one a few weeks back and genuinely think its great. When you want to generate a code you have to touch the token to show presence. I leave mine plugged into my PC and the LED blinks when I need to touch it.
There is a good chance you were not backing up the Authenticator app seeds, so loss of the token is the same situation as loss of phone now.
Does other stuff too but whatever
Ask employer to buy you a device for work.
You might have to carry 2 (but having work and personal data on teh same device is generally not a great idea, especially in big companies).
Or just use an onld 2G phone, none of the app-crapp works obiously, so you do not even need to explain 'complex things' to your boss/manager can't understand.
> Ask employer to buy you a device for work.
It speaks volumes about management's mindset when they expect employees to opt-in to the spyware app ecosystem on a personal device.
This is a litmus test. If management expects an employee to infect their personal device, because they don't want to provide a work device, then that employee should think long and hard about whether they're building their career with the right company.
My new employer want's me to install their app via sideloading! And then grant permissions to allow that base app to install extra modules FFS!
"more than 580,000 employees, trusted and use the ******** authenticator. The apps have gone through security testing, check, compliance etc., and I have not heard of any security breach due to the Authenticator application."
There never is an issue until the first time.
My employer tried for months and months to get me on Microsoft Authenticator on a personal device. I just politely let them know over and over that my personal phone is a flip phone / can't install apps, and the other devices I have are too old and don't meet the minimum requirements. How are they going to prove otherwise?
Or just use an old 2G phone
Using a dedicated 2G or 3G phone as a work phone in Australia has real merit. ;)
Certainly make for a quieter life since 2G, 3G networks (and recently non-VoLTE 4G) have been decommissioned for quite a while.
I miss my Nokia Asha 300 which I did use for work until 3G was pulled. Still have the handset.
So, let me get this straight
The maker of one single app is going to allow itself to wipe your phone if it doesn't like what it sees ?
Under what authority ?
Why do we put up with this bullshit ?
Re: So, let me get this straight
The maker of one single app is going to allow itself to wipe your phone if it doesn't like what it sees ?
As I read it this piece of Microslop shit doesn't wipe your phone or its arse; it just erases the stored credentials (and configurations?) for any work or educational Microslop account.
Perhaps a case of 'Render unto Caesar' — fine as long as the empire provides the device to be rendered unto.
Re: So, let me get this straight
No, the maker of app that handles MFA, will allow said app to wipe saved credentials for said Maker's authentication platform, mostly used to access resources hosted by said Maker.
I'm not saying it's right or wrong.
Hmm, is the data on a personal device Microsoft's to delete?
I'd have thought it belongs to the owner of the device, it exists on the device only as a result of the owner using the app to create it, same as using, say, a text editor to create a text file.
In which case, surely it'd be illegal (at least in UK) for MS to delete it.
Of course, MS is welcome to disable the account at the other end, then it's up to the organization's IT to sort out the MS-created mess.
So glad I've almost finished migrating all my stuff off MS, goodbye O365, no more revenue for MS, hello Proton and Libre office.
Hmm, how long before Microsoft Authenticator goofs...
and wipes a phone that is not jailbroken or rooted?
Do they save the Authenticator data in the cloud first or are they assuming no one will sue?
"other mobile operating systems, such as GrapheneOS, may also face restrictions"
Blocking devices which exist outside the identified, appified consumer ecosystem is a feature, not a bug.
It's not *YOUR* device. You're just the user. Even if you also pay for it.
This crap will continue until people want to feel sovereign in their devices and data, and are actually willing to draw red lines about unacceptable practices.
That won't happen. The vast majority of users want their bright, shiny object which controls their device and exfiltrates their data.