this post was submitted on 30 May 2024
210 points (94.1% liked)

Asklemmy

43790 readers
880 users here now

A loosely moderated place to ask open-ended questions

Search asklemmy ๐Ÿ”

If your post meets the following criteria, it's welcome here!

  1. Open-ended question
  2. Not offensive: at this point, we do not have the bandwidth to moderate overtly political discussions. Assume best intent and be excellent to each other.
  3. Not regarding using or support for Lemmy: context, see the list of support communities and tools for finding communities below
  4. Not ad nauseam inducing: please make sure it is a question that would be new to most members
  5. An actual topic of discussion

Looking for support?

Looking for a community?

~Icon~ ~by~ ~@Double_[email protected]~

founded 5 years ago
MODERATORS
 

So my company decided to migrate office suite and email etc to Microsoft365. Whatever. But for 2FA login they decided to disable the option to choose "any authenticator" and force Microsoft Authenticator on the (private) phones of both employees and volunteers. Is there any valid reason why they would do this, like it's demonstrably safer? Or is this a battle I can pick to shield myself a little from MS?

top 50 comments
sorted by: hot top controversial new old
[โ€“] [email protected] 2 points 5 months ago

I am in IT and I feel like I speak for the industry we don't care. Some of my customers have regulators who make arbitrary and capricious decisions with a minimal understanding of infosec but we have to keep the customer compliant.

[โ€“] [email protected] 5 points 5 months ago (1 children)

Grab the shelter app from f Droid, add the Play store in shelter, move over to the work side Play store and install the authenticator.

Pause your work apps except for when you need to use the authenticator.

Prosper???

[โ€“] [email protected] 1 points 5 months ago

Alternatively, in a similar fashion. Use "hail" to auto pause any app you want so they don't run in the background unintended.

https://f-droid.org/en/packages/com.aistra.hail/

[โ€“] [email protected] 7 points 5 months ago

Get a used /cheap phone or tablet, only turn it on or enable wifi when you need the app. Don't use it for anything else. I think that covers all the bases.

[โ€“] [email protected] 3 points 5 months ago

we have o365 and while i do have the authenticator, you should also be able to add a phone number or email address for text/email codes instead of the authenticator (i know my coworker doesn't have the authenticator but gets codes to her sms)

load more comments
view more: next โ€บ