MC1179154 – (Updated) Microsoft Authenticator app: Upcoming changes to jailbreak and root detection

cloudscout.one Icon

check before: 2026-02-28

Product:

Entra

Platform:

Android, iOS, Online, World tenant

Status:

Change type:

Admin impact, Feature update, Updated message, User impact

Links:

Details:

Summary:
Starting February 2026, Microsoft Authenticator will detect jailbroken/rooted devices and block Entra credentials on iOS and Android. The rollout includes warning, blocking, and wiping phases. This security feature is automatic with no opt-out. Users on non-jailbroken/rooted devices remain unaffected. Notify users and helpdesk accordingly.

Details:
Updated January 22, 2026: We have updated the timeline. Thank you for your patience.
[Introduction]
Starting end of February 2026, we will introduce jailbreak and root detection for Entra credentials in the Microsoft Authenticator app on both iOS and Android platforms. This change enhances security by preventing Entra credentials from functioning on jailbroken/rooted devices. All existing Entra credentials on jailbroken or rooted devices will be wiped to protect your organization. This capability is secure by default and does not require any admin configuration or control.
[When this will happen]
General Availability (Worldwide iOS) rollout begins in end of February 2026 and is expected to complete in May 2026 (previously April).
General Availability (Worldwide Android) rollout begins in March 2026 (previously February) and is expected to complete in June 2026 (previously April).

Change Category:
XXXXXXX ... free basic plan only

Scope:
XXXXXXX ... free basic plan only

Release Phase:

Created:
2025-10-25

updated:
2026-01-23

Task Type

XXXXXXX ... free basic plan only

Docu to Check

XXXXXXX ... free basic plan only

MS How does it affect me

XXXXXXX ... free basic plan only

MS Preperations

XXXXXXX ... free basic plan only

MS Urgency

XXXXXXX ... free basic plan only

MS workload name

XXXXXXX ... free basic plan only

Pictures

XXXXXXX ... free basic plan only

summary for non-techies**

Starting February 2026, Microsoft Authenticator will detect and block the use of Entra credentials on jailbroken or rooted devices in a phased rollout, ultimately wiping existing credentials from such devices.

Direct effects for Operations**

User Access Issues
Users on jailbroken or rooted devices will be blocked from accessing Entra credentials, leading to potential disruptions in their workflow and inability to perform tasks that require authentication.
   - roles: End Users, Helpdesk Staff
   - references: https://support.microsoft.com/account-billing/about-microsoft-authenticator-9783c865-0308-42fb-a519-8cf666fe0acc

Increased Helpdesk Inquiries
The rollout phases will likely lead to an increase in helpdesk inquiries as users receive warnings and experience blocks, requiring support for troubleshooting and guidance.
   - roles: Helpdesk Staff, IT Support
   - references: https://support.microsoft.com/account-billing/about-microsoft-authenticator-9783c865-0308-42fb-a519-8cf666fe0acc

User Experience Degradation
Users will experience a degraded experience with the Authenticator app due to warning messages and potential inability to log in, which may lead to frustration and decreased productivity.
   - roles: End Users, IT Managers
   - references: https://support.microsoft.com/account-billing/about-microsoft-authenticator-9783c865-0308-42fb-a519-8cf666fe0acc

Credential Loss
Existing Entra credentials will be wiped from jailbroken or rooted devices, resulting in loss of access to important resources and requiring users to re-register their credentials.
   - roles: End Users, IT Security
   - references: https://support.microsoft.com/account-billing/about-microsoft-authenticator-9783c865-0308-42fb-a519-8cf666fe0acc

Documentation Updates Required
Internal documentation referencing the use of Microsoft Authenticator will need to be updated to reflect the new changes, which may require additional time and resources.
   - roles: IT Documentation Team, Compliance Officers
   - references: https://support.microsoft.com/account-billing/about-microsoft-authenticator-9783c865-0308-42fb-a519-8cf666fe0acc

Configutation Options**

XXXXXXX ... paid membership only

Opportunities**

XXXXXXX ... free basic plan only

Potentional Risks**

XXXXXXX ... paid membership only

IT Security**

XXXXXXX ... paid membership only

explanation for non-techies**

XXXXXXX ... free basic plan only

** AI generated content. This information must be reviewed before use.

a free basic plan is required to see more details. Sign up here


A cloudsocut.one plan is required to see all the changed details. If you are already a customer, choose login.
If you are new to cloudscout.one please choose a plan.



change history

DatePropertyoldnew
2026-01-23MC Last Updated11/11/2025 21:33:492026-01-22T21:20:03Z
2026-01-23MC MessagesUpdated November 11, 2025: We have updated the content and the images below. Thank you for your patience.
[Introduction]
Starting February 2026, we will introduce jailbreak and root detection for Entra credentials in the Microsoft Authenticator app on both iOS and Android platforms. This change enhances security by preventing Entra credentials from functioning on jailbroken/rooted devices. All existing Entra credentials on jailbroken or rooted devices will be wiped to protect your organization. This capability is secure by default and does not require any admin configuration or control.
[When this will happen]
General Availability (Worldwide) rollout begins in February 2026 and is expected to complete in April 2026.
Updated January 22, 2026: We have updated the timeline. Thank you for your patience.
[Introduction]
Starting end of February 2026, we will introduce jailbreak and root detection for Entra credentials in the Microsoft Authenticator app on both iOS and Android platforms. This change enhances security by preventing Entra credentials from functioning on jailbroken/rooted devices. All existing Entra credentials on jailbroken or rooted devices will be wiped to protect your organization. This capability is secure by default and does not require any admin configuration or control.
[When this will happen]
General Availability (Worldwide iOS) rollout begins in end of February 2026 and is expected to complete in May 2026 (previously April).
General Availability (Worldwide Android) rollout begins in March 2026 (previously February) and is expected to complete in June 2026 (previously April).
2026-01-23MC End Time05/31/2026 09:00:002026-07-30T09:00:00Z
2026-01-23MC SummaryStarting February 2026, Microsoft Authenticator will detect jailbroken/rooted devices on iOS and Android, blocking and eventually wiping Entra credentials on such devices in a phased rollout through April 2026. This security feature is automatic, affects only compromised devices, and requires no admin configuration.Starting February 2026, Microsoft Authenticator will detect jailbroken/rooted devices and block Entra credentials on iOS and Android. The rollout includes warning, blocking, and wiping phases. This security feature is automatic with no opt-out. Users on non-jailbroken/rooted devices remain unaffected. Notify users and helpdesk accordingly.
2025-11-12MC prepareNotify users about this upcoming change.
Communicate to helpdesk staff that Authenticator will become unusable for Entra accounts on jailbroken or rooted devices.
Update internal documentation if you reference Authenticator usage.
No admin action is required to enable or configure this feature.
Learn more: About Microsoft Authenticator | Microsoft Support
[Compliance considerations]
No compliance considerations identified, review as appropriate for your organization.
https://support.microsoft.com/account-billing/about-microsoft-authenticator-9783c865-0308-42fb-a519-8cf666fe0acc
Notify users about this upcoming change. Users will see error messages or banners in the Authenticator app during warning or blocking phases. These screens are dismissible but indicate the device status.
Communicate to helpdesk staff that Authenticator will become unusable for Entra accounts on jailbroken or rooted devices.
Update internal documentation if you reference Authenticator usage.
No admin action is required to enable or configure this feature.
Learn more: About Microsoft Authenticator | Microsoft Support
[Compliance considerations]
No compliance considerations identified, review as appropriate for your organization.
https://support.microsoft.com/account-billing/about-microsoft-authenticator-9783c865-0308-42fb-a519-8cf666fe0acc
2025-11-12MC MessageTagNamesFeature update, User impact, Admin impactUpdated message, Feature update, User impact, Admin impact
2025-11-12MC SummaryStarting February 2026, Microsoft Authenticator will block Entra credentials on jailbroken/rooted iOS and Android devices through a phased rollout: warning, blocking, then wiping credentials. This security feature requires no admin setup. Users on compliant devices remain unaffected. Organizations should notify users and update documentation accordingly.Starting February 2026, Microsoft Authenticator will detect jailbroken/rooted devices on iOS and Android, blocking and eventually wiping Entra credentials on such devices in a phased rollout through April 2026. This security feature is automatic, affects only compromised devices, and requires no admin configuration.
2025-11-12MC Last Updated10/25/2025 00:09:112025-11-11T21:33:49Z
2025-11-12MC Messages[Introduction]
Starting February 2026, we will introduce jailbreak and root detection for Entra credentials in the Microsoft Authenticator app on both iOS and Android platforms. This change enhances security by preventing Entra credentials from functioning on jailbroken/rooted devices. All existing Entra credentials on jailbroken or rooted devices will be wiped to protect your organization. This capability is secure by default and does not require any admin configuration or control.
[When this will happen]
General Availability (Worldwide) rollout begins in February 2026 and is expected to complete in April 2026.
Updated November 11, 2025: We have updated the content and the images below. Thank you for your patience.
[Introduction]
Starting February 2026, we will introduce jailbreak and root detection for Entra credentials in the Microsoft Authenticator app on both iOS and Android platforms. This change enhances security by preventing Entra credentials from functioning on jailbroken/rooted devices. All existing Entra credentials on jailbroken or rooted devices will be wiped to protect your organization. This capability is secure by default and does not require any admin configuration or control.
[When this will happen]
General Availability (Worldwide) rollout begins in February 2026 and is expected to complete in April 2026.
2025-11-12MC TitleMicrosoft Authenticator app: Upcoming changes to jailbreak and root detection(Updated) Microsoft Authenticator app: Upcoming changes to jailbreak and root detection
2025-11-12MC How AffectWho is affected: All users of Microsoft Authenticator on iOS and Android whose Entra credentials are registered on jailbroken or rooted device.
What will happen:
The feature is secure by default.
Users on jailbroken or rooted devices will experience the following phased rollout:
Phase 1 - Warning Mode: Users receive a warning that their device is jailbroken or rooted and will be blocked in the future (screenshots 1-4):




Phase 2 - Blocking Mode: Users are blocked from registering Entra credentials or signing in via Authenticator (screenshots 5-6):


Phase 3 - Wipe Mode: Existing Entra credentials are wiped from jailbroken or rooted devices (screenshots 7-10):




Users on compliant (non-Jailbroken or non-rooted) devices will not be affected.
Who is affected: All users of Microsoft Authenticator on iOS and Android whose Entra credentials are registered on jailbroken or rooted device. This is going to be a continuous check.
What will happen:
The feature is secure by default and enabled to all customers. There is no opt-out capability..
Users on jailbroken or rooted devices will experience the following phased rollout. An estimated gap between 3 phases is ~ 1 month.
Phase 1 - Warning Mode: Users receive a warning that their device is jailbroken or rooted and will be blocked in the future (screenshots 1-4):




Phase 2 - Blocking Mode: Users are blocked from registering Entra credentials or signing in via Authenticator (screenshots 5-8):




Phase 3 - Wipe Mode: Existing Entra credentials are wiped from jailbroken or rooted devices (screenshots 9-11):



Users on non-Jailbroken or non-rooted devices will not be affected.

Last updated 4 weeks ago ago

Leave a Reply

Share to MS Teams

Login to your account

Welcome Back, We Missed You!