Microsoft Authenticator now blocks jailbroken and rooted devices
Authenticator now refuses to add or use work and school accounts on jailbroken or rooted phones. There's nothing to configure, but your service desk should know.
On this page
Jailbreak and root detection in Microsoft Authenticator is now generally available. On a jailbroken iPhone or rooted Android device, Authenticator blocks users from adding work or school accounts, and from using existing ones.
Why it matters
A jailbroken or rooted phone has its platform protections removed. Malware on such a device can do much more, including interfering with the app that's supposed to prove who the user is. Blocking these devices protects the integrity of MFA and passkeys held in Authenticator.
What you need to do
- No configuration. It's enforced automatically and can't be switched off.
- Brief the service desk. A user who suddenly can't use Authenticator may be on a modified device. The fix is a supported device or another method, not a workaround.
- Check for single points of failure. Users whose only method is Authenticator on a blocked device can't complete MFA. A temporary access pass gets them going while they register something else.
Why modified phones are risky
Jailbreaking an iPhone or rooting an Android phone removes protections the platform relies on: app sandboxing, secure storage and checks that apps haven't been tampered with. On such a device, malware can read data from other apps, intercept what's on screen, or interfere with the app that proves who the user is. An authenticator on that phone can no longer be trusted to be what it says it is.
Helping affected users
- Confirm the issue: the user will see Authenticator refuse to add or use their work account.
- Issue a Temporary Access Pass so they can sign in and register a different method.
- Offer an alternative: a supported phone, a FIDO2 security key, or Windows Hello for Business on their work PC.
- If the user restores their phone to a supported state, they can set Authenticator up again.
Check the bigger picture
If you use Intune, device compliance policies can also mark jailbroken or rooted devices as not compliant, which blocks access through Conditional Access. Together, the two cover both the authenticator and the corporate apps.