this post was submitted on 30 May 2024
210 points (94.1% liked)

Asklemmy

42480 readers
1791 users here now

A loosely moderated place to ask open-ended questions

Search asklemmy πŸ”

If your post meets the following criteria, it's welcome here!

  1. Open-ended question
  2. Not offensive: at this point, we do not have the bandwidth to moderate overtly political discussions. Assume best intent and be excellent to each other.
  3. Not regarding using or support for Lemmy: context, see the list of support communities and tools for finding communities below
  4. Not ad nauseam inducing: please make sure it is a question that would be new to most members
  5. An actual topic of discussion

Looking for support?

Looking for a community?

~Icon~ ~by~ ~@Double_[email protected]~

founded 5 years ago
MODERATORS
 

So my company decided to migrate office suite and email etc to Microsoft365. Whatever. But for 2FA login they decided to disable the option to choose "any authenticator" and force Microsoft Authenticator on the (private) phones of both employees and volunteers. Is there any valid reason why they would do this, like it's demonstrably safer? Or is this a battle I can pick to shield myself a little from MS?

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 22 points 1 month ago (22 children)

β‰₯ and force Microsoft Authenticator on the (private) phones of both employees and volunteers.

Refuse to use the service until they provide you with a work appointed phone. Volunteers admitedly have a more difficult time with that but as someone else said you can indeed do text/call options.

[–] [email protected] 2 points 1 month ago (4 children)

I work for a global company and help manage MFA for everyone...I use Google's authenticator on my personal phone as they didn't give me a work phone.

I still don't understand why a hardware token isn't being used. It's such a low cost option when compared to buying a phone and plan for a user.

[–] [email protected] 2 points 1 month ago (1 children)

Because you can’t call someone on a hardware token.

[–] [email protected] 1 points 1 month ago (1 children)

But not everyone needs to have a work phone, some just need to authenticate

[–] [email protected] 1 points 1 month ago* (last edited 1 month ago)

Then buy them an iPod touch.

load more comments (2 replies)
load more comments (19 replies)