Microsoft has announced that the Authenticator application will remove Entra (Azure Active Directory) credentials from iOS and Android devices that are detected as compromised, i.e., jailbroken or rooted.

Functionality

The Microsoft Authenticator security system is designed to detect tampering at the operating system level. When a jailbroken or rooted device is detected, access to corporate and school resources protected by Entra is initially blocked. Subsequently, the credentials are completely removed from the device.

Implications

This measure aims to protect sensitive data from potential threats arising from the use of insecure devices. Jailbroken or rooted devices are more vulnerable to malware and attacks, increasing the risk of unauthorized access to corporate information.