Any other authenticator also works with any MS service so there’s no reason at all to use the MS Authenticator unless you like handing over more data to MS for no reason.
EDIT: According to comments, your company might have the option to enforce usage of MS Authenticator only. But this doesn’t seem to be the default, at least in Germany where I’ve heard from 2 sources that they can use any authenticator app for M365 for example.
By the way, Graphene OS is NOT rooted, but what does truth or sane app behavior even mean anymore for Microslop in 2026… Just stop using that garbage.
Professionally I’ve had situations where Ms authenticator was the only option because the only 2FA they allow is push notifications on the authenticator app. :(
I even used freeotp+ for my ORG 2FA and aegis for my personal so I could easily keep them split ( and you can export / securely store the backups somewhere ).
Professionally I’ve had situations where Ms authenticator was the only option because the only 2FA they allow is push notifications on the authenticator app.
If a company requires me to install specific apps that may or may not work on my device, I expect that company to provide me with a device that can be set up for their stuff.
I’ve run two separate phones for nearly 15 years now: my personal phone, and a work-issued phone. The work phone is turned off and left on my night stand as soon as I get home, and only turned on again when I’m getting ready to go back to work. I don’t carry it 24/7 as some have been led to believe, for some reason. It’s really nice to have that separation. And work pays for it.
Peach. Separation is where it’s at, and companies should be required to provide technology required for work.
In an ideal world “No, I don’t want that on my personal device” should be sufficient, but it’s a lot harder to argue with “No, I literally cannot install that on my device; it’s incompatible. Provide an alternative for me.”
I’m finally taking steps to walk the walk re: phone separation—I’m hoping the Click Communicator pans out, since it seems like the ideal work phone. (I get a stipend for tech, so I can get whatever I want. I’ve been pocketing the extra cash, but it’s time to get an actual work phone.) I’m just hoping I can wait it out and ignore the Authenticator warnings until then, or maybe look into Magisk Hide or whatever.
We do need to get corps to move away from closed source protocols like MS, Google, Meta and others push notifications though. Those are not in anyway safer and are just basically trap to force people to use their apps
Anybody have a good reason to not use Authy? I’ve seen Aegis mentioned quite a bit but nobody supporting/dunking on Authy. I thought they were one of the more popular choices.
Use Aegis.
The MS Authenticator contains analytics & telemetry & way too many permissions and should not be used: https://reports.exodus-privacy.eu.org/en/reports/com.azure.authenticator/latest/ (it looks more like a scam than legitimate, but that’s exactly what Microslop is in 2026…)
For comparison, Aegis is a legitimate app that only does what it should do: https://reports.exodus-privacy.eu.org/en/reports/com.beemdevelopment.aegis/latest/#permissions
Any other authenticator also works with any MS service so there’s no reason at all to use the MS Authenticator unless you like handing over more data to MS for no reason. EDIT: According to comments, your company might have the option to enforce usage of MS Authenticator only. But this doesn’t seem to be the default, at least in Germany where I’ve heard from 2 sources that they can use any authenticator app for M365 for example.
By the way, Graphene OS is NOT rooted, but what does truth or sane app behavior even mean anymore for Microslop in 2026… Just stop using that garbage.
Agree for personal use.
Professionally I’ve had situations where Ms authenticator was the only option because the only 2FA they allow is push notifications on the authenticator app. :(
I even used freeotp+ for my ORG 2FA and aegis for my personal so I could easily keep them split ( and you can export / securely store the backups somewhere ).
Time to get corps to ditch Microsoft >.>
If a company requires me to install specific apps that may or may not work on my device, I expect that company to provide me with a device that can be set up for their stuff.
I’ve run two separate phones for nearly 15 years now: my personal phone, and a work-issued phone. The work phone is turned off and left on my night stand as soon as I get home, and only turned on again when I’m getting ready to go back to work. I don’t carry it 24/7 as some have been led to believe, for some reason. It’s really nice to have that separation. And work pays for it.
My employer is government so they do provide an alternative. If you can’t use Microsoft authenticator, you can get an authentication phone call
Peach. Separation is where it’s at, and companies should be required to provide technology required for work.
In an ideal world “No, I don’t want that on my personal device” should be sufficient, but it’s a lot harder to argue with “No, I literally cannot install that on my device; it’s incompatible. Provide an alternative for me.”
I’m finally taking steps to walk the walk re: phone separation—I’m hoping the Click Communicator pans out, since it seems like the ideal work phone. (I get a stipend for tech, so I can get whatever I want. I’ve been pocketing the extra cash, but it’s time to get an actual work phone.) I’m just hoping I can wait it out and ignore the Authenticator warnings until then, or maybe look into Magisk Hide or whatever.
We do need to get corps to move away from closed source protocols like MS, Google, Meta and others push notifications though. Those are not in anyway safer and are just basically trap to force people to use their apps
Anybody have a good reason to not use Authy? I’ve seen Aegis mentioned quite a bit but nobody supporting/dunking on Authy. I thought they were one of the more popular choices.
Authy is closed source and owned by Twilio, a publicly-traded company.
Aegis is FOSS.
Do what you will with this info.
Seems like Authy doesn’t have a feature to export to another app. Guess you re-enable 2fa on each account to move to something like aegis.
That’s exactly what I did. It was a pain because I have so many 2FA-enabled accounts, but it was absolutely worth it.
Yeah I wish I knew, I was using Authy because as far as I knew it was that Google or Microsoft.
Authy also doesn’t work on GrapheneOS.
EDIT: And Authy scrapped their desktop apps. I’m using ente instead.
https://f-droid.org/packages/io.ente.auth/
That makes sense. Thanks! I don’t use graphene but I do use authy and wondered if I should be reconsidering my choices 😅