azureblog.co.uk
← cd ~/posts

Microsoft Authenticator now blocks jailbroken and rooted devices

Authenticator now refuses to add or use work and school accounts on jailbroken or rooted phones. There's nothing to configure, but your service desk should know.

2 min read✓ checked 22 Jul 2026Entra ID · Security · What's new
Part 5 of 6 in Passwordless rollout
On this page
  1. Why it matters
  2. What you need to do
  3. Why modified phones are risky
  4. Helping affected users
  5. Check the bigger picture

Jailbreak and root detection in Microsoft Authenticator is now generally available. On a jailbroken iPhone or rooted Android device, Authenticator blocks users from adding work or school accounts, and from using existing ones.

Is the phone jailbroken or rooted?
NoWork accounts work as normal.
YesAuthenticator blocks adding or using work and school accounts.
What happens when a user opens Authenticator.

Why it matters

A jailbroken or rooted phone has its platform protections removed. Malware on such a device can do much more, including interfering with the app that's supposed to prove who the user is. Blocking these devices protects the integrity of and held in Authenticator.

What you need to do

  • No configuration. It's enforced automatically and can't be switched off.
  • Brief the service desk. A user who suddenly can't use Authenticator may be on a modified device. The fix is a supported device or another method, not a workaround.
  • Check for single points of failure. Users whose only method is Authenticator on a blocked device can't complete MFA. A gets them going while they register something else.

Why modified phones are risky

Jailbreaking an iPhone or rooting an Android phone removes protections the platform relies on: app sandboxing, secure storage and checks that apps haven't been tampered with. On such a device, malware can read data from other apps, intercept what's on screen, or interfere with the app that proves who the user is. An authenticator on that phone can no longer be trusted to be what it says it is.

Helping affected users

  1. Confirm the issue: the user will see Authenticator refuse to add or use their work account.
  2. Issue a Temporary Access Pass so they can sign in and register a different method.
  3. Offer an alternative: a supported phone, a security key, or on their work PC.
  4. If the user restores their phone to a supported state, they can set Authenticator up again.

Check the bigger picture

If you use Intune, device can also mark jailbroken or rooted devices as not compliant, which blocks access through . Together, the two cover both the authenticator and the corporate apps.

Next in Passwordless rollout · part 6 of 6Microsoft is retiring its own SMS and voice MFA. Here's your plan. →