JdeBP · @JdeBP
117 followers · 3620 posts · Server mastodonapp.uk

@Erased_Citizen I regard it as Microsoft's equivalent of ed(1) in its error handling.

It's sole failure modes are either sit and wait for ever or timeout with no clue given as to what went wrong. And in several places Microsoft's applications won't tell the user that it's even waiting for Authenticator, but will just show a progress bar or a spinning mouse pointer.

I count my lucky stars that it's someone else's job at my company to manage it.

#MicrosoftAuthenticator

Last updated 2 years ago

JdeBP · @JdeBP
117 followers · 3620 posts · Server mastodonapp.uk

@Erased_Citizen Easily, if my experience is any guide.

Just requiring Microsoft Authenticator for two logins on two different machines simultaneously is enough to make it fail both of them. And if it's something like RDP where it automatically re-tries 5 times after a network outage, and you had about 6 sessions going, it's a long road back to where it will authenticate again.

#MicrosoftAuthenticator

Last updated 2 years ago

Micael Söder · @micael
2 followers · 2 posts · Server mastodon.nu

forcing you to have a secondary e-mail for recovery. Why!? Want to add a security key? You can't use . How about paswordless sign-in... required.

😞 😠

#MicrosoftAuthenticator #linux #microsoft

Last updated 2 years ago

Matt Hardy · @TechnicalAdept
10 followers · 107 posts · Server awscommunity.social

I put some words on page so other people can read what I was thinking: "Microsoft back down on plans to enforce Microsoft Authenticator number matching" technicaladept.com/index.php/2

#microsoft #authenticator #MicrosoftAuthenticator #security #mfa

Last updated 2 years ago

Campah · @campah
2 followers · 16 posts · Server mas.to

Bye bye , it was nice knowing you while you were useful…

#MicrosoftAuthenticator

Last updated 2 years ago

Filip · @hhg
6 followers · 39 posts · Server infosec.exchange

Since a lot of eyes are on and in general right now, hopefully, we can bring some good out of it and share best practices/tips for authentication, for everyone to be more secure.

  1. Use a password manager. Yes, they can be breached, but they are 1000x better than memory or similar passwords everywhere. The ones I see recommended usually are and (which I personally support and suggest, and it's )
  2. Combine the step above and all logins where possible with (usually ). I saw and recommended multiple times. Personally, I have only used and (Android only), both of which I suggest (Aegis is more technically involved, as there is no cloud to backup to, you're in charge of managing your backups).
  3. I also think an email address used only as a recovery option for your main one/password manager is a good idea. Have a password as strong as the one on your password manager. Use 2FA on it and don't use it for anything else.
  4. If you have the money and are open to making your life a tad bit more difficult in exchange for more protection, you can opt for physical MFA keys, such as .

I'm by no means an expert in or , but I do believe I do some things right, and I am optimistic that at least some will find posts like this at least somewhat useful. Please let me know if I'm missing something or if I am flat out wrong with some of the things above.

#lastpass #passwordmanagers #1password #bitwarden #foss #mfa #2fa #authy #googleauthenticator #MicrosoftAuthenticator #aegis #yubikey #cybersecurity #infosec

Last updated 2 years ago

Hans Dickel · @recursivegeek
5 followers · 18 posts · Server twit.social

I now see articles from December 12 announcing Microsoft Authenticator is leaving watchOS. Sad. I use my watch many times daily for authenticating so I don’t have to grab my phone. Disappointing. Apple and Microsoft need to make this work.

#MicrosoftAuthenticator #watchos

Last updated 2 years ago

André · @asltf
334 followers · 417 posts · Server toot.bike

@admin You can't register a FIDO key unless you have a working TOTP device (, + ..) registered

#GoogleAuthenticator #MicrosoftAuthenticator #FreeOTP

Last updated 2 years ago

toot.bike Admin Team · @admin
178 followers · 86 posts · Server toot.bike

Please activate 2 factor authentication . You can either use an app like or or a hardware dongle like the or the . Best probably is to use the hardware key and have the app as backup. Thanks for helping to make this Mastodon instance a safer place.

#2fa #GoogleAuthenticator #MicrosoftAuthenticator #YubiKey #NitroKey

Last updated 2 years ago

Jef Kazimer😶‍🌫️ · @JefTek
313 followers · 212 posts · Server infosec.exchange

With the ever increasing attacks on users, moving to is a must in order to reduce the attack surface of just relying on a password to secure access to resources. Implementing that is enforced all the time relies on also having a good user experience, which gave rise to mobile authenticator apps since many users always have their phones with them. However it also gave rise to and griefing to get those users to approve. With the recent GA of orgs can enable number match and context for the push notification to further improve the of the users by avoiding the blind approval of a push notification.

🔥 See the post on the AzureAD blog here and go enable these settings for your organization techcommunity.microsoft.com/t5

#multifactorauthentication #mfa #mfabombing #MicrosoftAuthenticator #azuread #security #microsoft #office365 #o365 #cloudsecurity

Last updated 2 years ago