Microsoft Authenticator might exclude GrapheneOS in the future due to root detection

https://lemmy.zip/post/60254818

Microsoft Authenticator might exclude GrapheneOS in the future due to root detection - Lemmy.zip

Lemmy

So win win.
Unfortunately not for me. I use Graphene and my company uses M$croslop.

Work stuff should be on a work phone.

I don’t understand why either the worker or the company would ever allow the use of personal devices for work.

Because they are cheap and their tech lead is probably incompetent.
This is Walmart in a nutshell. A majority of the work phones at my store (used for stuff like inventory management) are Samsung Galaxy XCover Pros from like 2016. They were trash the day they released and they’re especially trash now. The company is very slowly replacing them with Pixel 8s (like one every six months comes in). It is legitimately frustrating.
Why pixel 8 in particular? Wouldn’t an A series pixel be cheaper.

Unless on Motorola devices (soon).

I hope it’s like FairPhone where you get to choose android or Murena/e/

We wouldn’t want any Graphene OS device to fulfill the requirements necessary to be certified. That would make it useless.

‘Rooted’ doesn’t mean rooted, it means the Google API it checks against says no. And is unlikely to say yes on any device that isn’t ‘official Android’, with Google Apps having System access.

This is what I fear will happen to GOS on Motos. Google decides to mark them as rooted so buh-bye banking apps and others that require a “secure” os.
Except they’re not rooted - GOS devs don’t even approve of root usage
It doesn’t matter if they are or not. Google can deem them modified or not secure devices and they can do fuck all about it.
The difference being that Motorola is a well established device manufacturer and not just a community project with minimal funding. Google using play integrity to exclude a competitor could be very easily seen as an abuse of market power and they already have problems with antitrust laws.
They check through Google Play services, Graphene has play services in a sandbox, it can’t see enough to report the security of the device accurately
Oh this is some bullshit. Anyone know of a decent FOSS(ish) alternative?
I’ve heard Aegis being mentioned.
ive used it for months, no issues at all
Cool, the fewer people using Microslop apps, the better.
That’s cool. Guess my company is going to have to send me a new phone.

Use Aegis.

The MS Authenticator contains analytics & telemetry & way too many permissions and should not be used: reports.exodus-privacy.eu.org/en/…/latest/ (it looks more like a scam than legitimate, but that’s exactly what Microslop is in 2026…)

For comparison, Aegis is a legitimate app that only does what it should do: reports.exodus-privacy.eu.org/en/…/latest/#permis…

Any other authenticator also works with any MS service so there’s no reason at all to use the MS Authenticator unless you like handing over more data to MS for no reason. EDIT: According to comments, your company might have the option to enforce usage of MS Authenticator only. But this doesn’t seem to be the default, at least in Germany where I’ve heard from 2 sources that they can use any authenticator app for M365 for example.

By the way, GrapheneOS is NOT rooted, but what does truth or sane app behavior even mean anymore for Microslop in 2026… Just stop using that garbage.

Report for com.azure.authenticator 6.2602.0889

Known trackers, permissions and informations about this specific version of this application

εxodus

Agree for personal use.

Professionally I’ve had situations where Ms authenticator was the only option because the only 2FA they allow is push notifications on the authenticator app. :(

I even used freeotp+ for my ORG 2FA and aegis for my personal so I could easily keep them split ( and you can export / securely store the backups somewhere ).

Time to get corps to ditch Microsoft >.>

Professionally I’ve had situations where Ms authenticator was the only option because the only 2FA they allow is push notifications on the authenticator app.

If a company requires me to install specific apps that may or may not work on my device, I expect that company to provide me with a device that can be set up for their stuff. Or an alternative, like a hardware RSA token.

I’ve run two separate phones for nearly 15 years now: my personal phone, and a work-issued phone. The work phone is turned off and left on my night stand as soon as I get home, and only turned on again when I’m getting ready to go back to work. I don’t carry it 24/7 as some have been led to believe, for some reason. It’s really nice to have that separation. And work pays for it.

My employer is government so they do provide an alternative. If you can’t use Microsoft authenticator, you can get an authentication phone call