267
101

Microsoft Authenticator might exclude GrapheneOS in the future due to root detection

17h 36m ago by lemmy.zip/u/schizoidman in android@lemdro.id from piunikaweb.com

Due to new Microsoft policies, the Microsoft Authenticator app might not work on GrapheneOS. It's a phased rollout, beginning February 2026.

So win win.

Unfortunately not for me. I use Graphene and my company uses M$croslop.

Work stuff should be on a work phone.

I don't understand why either the worker or the company would ever allow the use of personal devices for work.

Some businesses don't pay for phones but agreed

That's their point. If the company requires you to use a phone, they need to provide it.

They can also just let you go for someone else who has no clue about this and gladly would use their private phone for work. Depends on the job and company, of course.

That's dangerous thinking; "if I don't then someone else will." That's a common excuse that thieves use. And it's you doing the work of your oppressor.

Standing up for what you believe in isn't always easy, but it's always the right choice.

You don't want to work for a cheap company.

Because they are cheap and their tech lead is probably incompetent.

This is Walmart in a nutshell. A majority of the work phones at my store (used for stuff like inventory management) are Samsung Galaxy XCover Pros from like 2016. They were trash the day they released and they're especially trash now. The company is very slowly replacing them with Pixel 8s (like one every six months comes in). It is legitimately frustrating.

Why pixel 8 in particular? Wouldn't an A series pixel be cheaper.

my work pays my cell phone bill if I install Microsoft teams, and frankly that's a pretty good deal

With that money, get a second one and it's it only during work ours. Doesn't even need connection, use WiFi of tethering.

that sounds annoying. I'd rather just have it all on the same device. I can enable and disable work apps on a schedule if I'm bothered. I don't want to deal with two devices really

So does my company

So didn't have to instsll intune or anything?

yeah but you can disable most of it's invasive permissions so I'm ok with it

Not all works would allow it, but why not Graphene on work phones.

What happens if the worker doesn't have a smartphone, or has one, it breaks and they don't have money to buy another for while, or what if they install a random app that encrypts their mailbox?

Even if you live in a 3rd world country where employers can force it, it's a stupid decision for the business.

I don't understand your line of questioning. If a bad thing happens then a bad thing happens. Potential for bad things indeed makes companies likely to lock down devices if they provide them, hence the qualifier "not all works would allow it." From an employee perspective, if you have the freedom to do it then more secure OS is more secure.

I can tell you what we do. Here's your yubikey. Then most find a new phone after a couple weeks.

It's a dark pattern but you can use any MFA provider with Microsoft services.

Not necessarily. Microsoft's authenticator has an option where you have to tap a notification to approve, which isn't a standard TOTP thing. If your company requires that version of MFA, you pretty much have to use Microsoft's authenticator.

Aw shit, this sucks because my company uses this authentication method.

I guess when the change finally happens I'll just be saying 'you owe me a phone for this'. Absolutely no way i am going back to Android just for this on my personal phone.

One possible workaround is to add more options to your security info in your work account. For example, I added my number and also a specific password as an option last year when I moved onto Graphene and had to update that info. Would that be an option?

Unsure if that would even work or if those options are more for account recovery (when no longer have access to a specific device)

If it cane down to it, I'm sure you could find an old phone or tablet to use just for that for work.

Yeah, this is what might be the final outcome

If i say give me a phone and they say "no, come into the office instead of working from home", I will produce an old phone faster than ya ckuld blink lol

MS MFA allows to use a different Authenticator App. On the step called "Start by getting the app" you just need to press the blue text above the "next" button which spells "I want to use a different authenticator app", there you can use whatever you prefer, even WinAuth works with this method.

This depends on settings I think. I've had that option not being available on a certain client where I could only use their authenticator app.

My school_requires_ MS authentication and removed this ability and broke any third party authenticators currently in use.

I've used the FOSS app Aegis on Android for MFA of what I think was a Microsoft login (it was a website for a railway technical authority in the UK).

The app is on fdroid:

https://f-droid.org/packages/com.beemdevelopment.aegis

Thats intetesting, Iam using aegis in private.

So does mine, and Oracle.... But that just means no slop installed

Can't use freeOPT?

Not sure about this one, but many don't expose the key used to generate the codes, it's linked to your user.

So it's not trivial/possible to use a FOSS alternative.

This happens with okta too.

No MS authenticator also requires internet and gives saysbis this you. Also requires a number.

Gursd they'll have to buy you a work phone

No they haven't . I get every month money for using my device for work (bring your own device).

Is that money enough to buy a phone? If not, they're not paying you enough for that.

If so, then you should actually spend that money on what it's meant for

You can use a different authenticator with M$ accounts. Just choose to set up with a different app. Aegis is nice.

Iam using aegis for my private logins. As I understand does Aegis not support MS Entra Logins.

Great, so you have nothing to worry about, unless your Graphene phone is rooted. (Which would defeat the entire point)

The article is shit. Microsoft is not blocking any GrapheneOS. It is only blocking rooted phones.

"root detection" is not actually detecting root as that is very difficult it's detecting an unlocked bootloader or modified software that didn't come on your phone(like a custom rom such as graphene os)

Old phone with remote desktop.

Works like a charm for many of these types of things. You can also forward notifications into NTFY or Matrix.

Do they mandate the use of MS Authenticator specifically, though?

The option to add that restriction is definitely there, but it's worth checking your account settings to see if it'll let you use a different MFA option.

The whole company uses Microsoft. I guess there is no chance for me.

That's fine.

Any job that wants you to use certain software can provide a device it'll run on for you.

Amen to that. Even if your computers will run it, provide the device. I'm not installing shit on my home computers.

My job has suggested it to me. I say "you know how all these computers run Windows?" They nod. "Mine doesn't. It's a Mac." That usually shuts them up. Never mind that most of what we run will, in fact, run on a Mac, and there's very little a shitty Wintel box mass produced for the enterprise can do that my Mac can't do. I mean, I can run Deus Ex natively on the work computer, if I wanna catch hell for it. (But it would be fucking hilarious, especially if I'm at the part where JC Denton hands in his "resignation.")

and it goes in an old microwave in the laundry room when not in use. right? this isn't crazy in this day and age is it?

IS IT???

Trunk of the car is fine if you just head straight home. That's out of mic range. And your employer is going to know your home address anyway so location access is whatever.

Bring it inside when you go on a road trip.

Yep! You want me to use your microslop on your hardware at your company, fine.

A company that has you use your personal device is an awful company and huge red flags in terms of privacy.

Use Aegis.

The MS Authenticator contains analytics & telemetry & way too many permissions and should not be used: https://reports.exodus-privacy.eu.org/en/reports/com.azure.authenticator/latest/ (it looks more like a scam than legitimate, but that's exactly what Microslop is in 2026...)

For comparison, Aegis is a legitimate app that only does what it should do: https://reports.exodus-privacy.eu.org/en/reports/com.beemdevelopment.aegis/latest/#permissions

Any other authenticator also works with any MS service so there's no reason at all to use the MS Authenticator unless you like handing over more data to MS for no reason.

By the way, Graphene OS is NOT rooted, but what does truth or sane app behavior even mean anymore for Microslop in 2026... Just stop using that garbage.

Agree for personal use.

Professionally I've had situations where Ms authenticator was the only option because the only 2FA they allow is push notifications on the authenticator app. :(

I even used freeotp+ for my ORG 2FA and aegis for my personal so I could easily keep them split ( and you can export / securely store the backups somewhere ).

Time to get corps to ditch Microsoft >.>

We do need to get corps to move away from closed source protocols like MS, Google, Meta and others push notifications though. Those are not in anyway safer and are just basically trap to force people to use their apps

Professionally I’ve had situations where Ms authenticator was the only option because the only 2FA they allow is push notifications on the authenticator app.

If a company requires me to install specific apps that may or may not work on my device, I expect that company to provide me with a device that can be set up for their stuff. Or an alternative, like a hardware RSA token.

I've run two separate phones for nearly 15 years now: my personal phone, and a work-issued phone. The work phone is turned off and left on my night stand as soon as I get home, and only turned on again when I'm getting ready to go back to work. I don't carry it 24/7 as some have been led to believe, for some reason. It's really nice to have that separation. And work pays for it.

Anybody have a good reason to not use Authy? I've seen Aegis mentioned quite a bit but nobody supporting/dunking on Authy. I thought they were one of the more popular choices.

Authy also doesn't work on GrapheneOS.

EDIT: And Authy scrapped their desktop apps. I'm using ente instead.

https://f-droid.org/packages/io.ente.auth/

That makes sense. Thanks! I don't use graphene but I do use authy and wondered if I should be reconsidering my choices 😅

Authy is closed source and owned by Twilio, a publicly-traded company.

Aegis is FOSS.

Do what you will with this info.

Interesting considering grapheneOS does not actually support rooting. 

This is the thing that kills me about the corporate anti-GrapheneOS sentiment. It is 100% a more secure phone, and yet every measure they implement against it cites security as a reason. Total and absolute bullshit.

I mean, they argue against rooted phones as a security reason, but my rooted phones used to be much more secure than they were when they were stock.

Just more of the same idiots ruining shit for everybody.

Because it isn't really about security. It is about control.

Which means the entire article is bullshit.

It literally states that Microsoft changes its policy to not allow rooted devices. So GrapheneOS has nothing to worry. It doesn't affect them. Why does the article mention it then at all?

Seems like a clickbait article

This is what I fear will happen to GOS on Motos. Google decides to mark them as rooted so buh-bye banking apps and others that require a "secure" os.

Except they're not rooted - GOS devs don't even approve of root usage

It doesn't matter if they are or not. Google can deem them modified or not secure devices and they can do fuck all about it.

The difference being that Motorola is a well established device manufacturer and not just a community project with minimal funding. Google using play integrity to exclude a competitor could be very easily seen as an abuse of market power and they already have problems with antitrust laws.

Not with the current trump administration. They can do whatever they want

Another banking app thread, fun! Don't use phones for banking. One just trades privacy for perceived convenience. For "safety" you give your bank:

  • Unnecessary lower-level system access than normal apps, for SAFETY!
  • Your location as often as they can harvest it
  • What apps you have installed
  • Any metadata they can exfiltrate through trackers in the app that can be mated with metadata from other app trackers
  • Any personal information they can gather from your phone

Furthermore, if you use tap-to-pay, which some banks require their app be installed to use, you're then giving every transaction you do, with or without tap-to-pay, to the operating system provider and any third parties along the way. Use your credit card at a store and the phone's at home? That transaction still gets scooped up.

Finally, you have this object you always carry with you, that has access to all your financial information, that a bad guy just has to punch you in the face to get you to log into your bank and delete all your money. Bravo! With a card, it can be shut off afterwards, and the bank can mark any transactions happening afterwards as fraudulent. With a phone app, they can Zelle themselves your money and the forward it to some cryptocurrency and good luck. Then clean out your RobinHood, your DraftKings, your CoinBase, your 401k, and anything else they find along the way.

Use the bank webapp if one is desperate.

Banking. On. Phones. Is. Stupid.

All these banking apps need google play for the freaking 2 factor code sent via text to work.

Why can't I setup TOTP for these? Banks I am looking at you.

Always has been.

Banking on a phone is insecure, and this is one reason. Never use banking on mobile.

Don't see how banking on phone is anybless secure then a computer.

You're letting the bank know everything about you. What apps you have installed, how you use your phone, where you go, you're just letting them have access to your entire life for mild convenience. Just use the web site and make an icon on the home screen to get to it.

How long is your password on your phone? How long is your password on your computer?

Unless on Motorola devices (soon).

I hope it's like FairPhone where you get to choose android or Murena/e/

Make no mistake. If Google does not certify GrapheneOS on Motorola, these devices will be flagged as modified by Googles API just like on any other device.

So much for Android OPEN SOURCE Project, huh?

Only "open source" if Google gets to profit from it?

Works for me.

We wouldn't want any Graphene OS device to fulfill the requirements necessary to be certified. That would make it useless.

'Rooted' doesn't mean rooted, it means the Google API it checks against says no. And is unlikely to say yes on any device that isn't 'official Android', with Google Apps having System access.

Googles been getting in trouble for requiring Google apps to he certified. So maybe they allow grapheneos through to say see we don't knowing it well be very niche.

Like my other comment said to someone else, so much for Android "OPEN SOURCE" Project, huh? Only OK if its stuffed with Google shit to make money from?

Honestly thank you for posting this. Lest I would've lost my Google and Microslop account.

Use your work phone.

I don't need a Microsoft account and if Google insists, I will kill my account with them as well.

That doesn't make sense to me, afaiu :

GrapheneOS is NOT rooted by default, and they explicit recommend NOT to do it, because it invalidates a huge part of their privacy guarantees.

Yeah, and Microsoft policy is just about rooted phones.

There isn't any reason to mention GrapheneOS, unless it is to generate unwarranted outrage.

Which seems to be working on a lot of folk on here.

Well it could just be part of the collective corporate alliance that will always do anything they can to make any kind of freedom cost more for everyone. GrapheneOS is taking your freedom and not feeding on the corporate-issued fodder, and well, they don’t like that. So this is just one more small difficulty added to that choice.

This kind of thing is only the beginning. It won’t be long before absolutely nothing will work on any freedom-oriented OS, software, hardware etc.

Some fires need to start, and soon.

Cool, the fewer people using Microslop apps, the better.

That's cool. Guess my company is going to have to send me a new phone.

Oh this is some bullshit. Anyone know of a decent FOSS(ish) alternative?

I've heard Aegis being mentioned.

Been using it for years. No issues at all.

Yes I love Aegis.

Used for years. The best.

I have been usingnit for Ages, haven't had a problem.

ive used it for months, no issues at all

Aegis

Microsoft Authenticator do support a closed proprietary protocol to interface with Microsoft/Azure logins instead of TOTP and HOTP, which requires an internet connection. So if you need this, no luck for you. If instead you just need TOTP and/or HOTP, then take a look at aegis or mauth.

Ente Auth

Oh no

Anyway

Microslop authenticator might not work for my zero Microslop accounts, lack of Microslop sloperating system, OR their piece of shit cloud platform that I refuse to touch?

WHAT WILL I DO

Microslop Authenticator might exclude GrapheneOS in the future due to root detection

So don't have a rooted GrapheneOS and everything will be fine.