check before: 2026-02-01
Product:
Entra
Platform:
Android, iOS, Online, World tenant
Status:
Change type:
Admin impact, Feature update, Updated message, User impact
Links:
Details:
Summary:
Starting February 2026, Microsoft Authenticator will detect jailbroken/rooted devices on iOS and Android, blocking and eventually wiping Entra credentials on such devices in a phased rollout through April 2026. This security feature is automatic, affects only compromised devices, and requires no admin configuration.
Details:
Updated November 11, 2025: We have updated the content and the images below. Thank you for your patience.
[Introduction]
Starting February 2026, we will introduce jailbreak and root detection for Entra credentials in the Microsoft Authenticator app on both iOS and Android platforms. This change enhances security by preventing Entra credentials from functioning on jailbroken/rooted devices. All existing Entra credentials on jailbroken or rooted devices will be wiped to protect your organization. This capability is secure by default and does not require any admin configuration or control.
[When this will happen]
General Availability (Worldwide) rollout begins in February 2026 and is expected to complete in April 2026.
Change Category:
XXXXXXX ... free basic plan only
Scope:
XXXXXXX ... free basic plan only
Release Phase:
Created:
2025-10-25
updated:
2025-11-12
Task Type
XXXXXXX ... free basic plan only
Docu to Check
XXXXXXX ... free basic plan only
MS How does it affect me
XXXXXXX ... free basic plan only
MS Preperations
XXXXXXX ... free basic plan only
MS Urgency
XXXXXXX ... free basic plan only
MS workload name
XXXXXXX ... free basic plan only
Pictures
XXXXXXX ... free basic plan only
summary for non-techies**
XXXXXXX ... free basic plan only
Direct effects for Operations**
Device Compatibility Issues
Users with jailbroken or rooted devices will be blocked from accessing Entra credentials, leading to potential loss of access to critical applications and services.
- roles: End Users, Helpdesk Staff
- references: https://support.microsoft.com/account-billing/about-microsoft-authenticator-9783c865-0308-42fb-a519-8cf666fe0acc
User Experience Disruption
Users will receive warnings and error messages during the phased rollout, causing confusion and frustration among those unaware of the changes.
- roles: End Users, IT Support
- references: https://support.microsoft.com/account-billing/about-microsoft-authenticator-9783c865-0308-42fb-a519-8cf666fe0acc
Increased Helpdesk Inquiries
The rollout will likely lead to an increase in helpdesk inquiries as users seek assistance regarding access issues and error messages related to their devices.
- roles: Helpdesk Staff, IT Support
- references: https://support.microsoft.com/account-billing/about-microsoft-authenticator-9783c865-0308-42fb-a519-8cf666fe0acc
Loss of Data Access
Existing Entra credentials will be wiped from jailbroken or rooted devices, resulting in potential data loss for users who do not have backups.
- roles: End Users, Data Managers
- references: https://support.microsoft.com/account-billing/about-microsoft-authenticator-9783c865-0308-42fb-a519-8cf666fe0acc
Documentation Updates Required
Internal documentation referencing the use of Microsoft Authenticator will need to be updated to reflect the new security measures, requiring time and resources.
- roles: IT Documentation Team, Compliance Officers
- references: https://support.microsoft.com/account-billing/about-microsoft-authenticator-9783c865-0308-42fb-a519-8cf666fe0acc
Configutation Options**
XXXXXXX ... paid membership only
Opportunities**
User Education and Communication
With the upcoming changes in the Microsoft Authenticator app, there is an opportunity to enhance user education regarding device security. Providing clear communication about the implications of using jailbroken or rooted devices can improve user experience and compliance with security policies.
- next-steps: Develop a communication plan that includes emails, webinars, and training sessions to inform users about the changes and the importance of device security. Create easy-to-understand materials that explain how to check if their device is jailbroken/rooted and the steps to take if it is.
- roles: IT Support, Security Team, Training Coordinators
- references: https://support.microsoft.com/account-billing/about-microsoft-authenticator-9783c865-0308-42fb-a519-8cf666fe0acc
Helpdesk Preparedness
As the Authenticator app becomes unusable for users with jailbroken or rooted devices, preparing the helpdesk staff to handle user inquiries and support requests will enhance operational efficiency and user satisfaction.
- next-steps: Conduct training sessions for helpdesk staff to familiarize them with the changes, potential user issues, and troubleshooting steps. Create a knowledge base article to help staff respond to common questions related to the new feature.
- roles: Helpdesk Staff, IT Support Managers
- references: https://support.microsoft.com/account-billing/about-microsoft-authenticator-9783c865-0308-42fb-a519-8cf666fe0acc
Internal Documentation Update
Updating internal documentation regarding the use of Microsoft Authenticator and the new security measures will ensure that all employees are informed and aligned with the new protocols, improving overall compliance and security posture.
- next-steps: Review and revise all internal documentation related to Microsoft Authenticator, ensuring it reflects the upcoming changes. Distribute the updated documentation to all relevant stakeholders and ensure it is accessible in internal resources.
- roles: IT Administrators, Compliance Officers
- references: https://support.microsoft.com/account-billing/about-microsoft-authenticator-9783c865-0308-42fb-a519-8cf666fe0acc
Potentional Risks**
XXXXXXX ... paid membership only
IT Security**
XXXXXXX ... paid membership only
explanation for non-techies**
XXXXXXX ... free basic plan only
** AI generated content. This information must be reviewed before use.
a free basic plan is required to see more details. Sign up here
A cloudsocut.one plan is required to see all the changed details. If you are already a customer, choose login.
If you are new to cloudscout.one please choose a plan.
change history
| Date | Property | old | new |
| 2025-11-12 | MC prepare | Notify users about this upcoming change.
Communicate to helpdesk staff that Authenticator will become unusable for Entra accounts on jailbroken or rooted devices. Update internal documentation if you reference Authenticator usage. No admin action is required to enable or configure this feature. Learn more: About Microsoft Authenticator | Microsoft Support [Compliance considerations] No compliance considerations identified, review as appropriate for your organization. https://support.microsoft.com/account-billing/about-microsoft-authenticator-9783c865-0308-42fb-a519-8cf666fe0acc | Notify users about this upcoming change. Users will see error messages or banners in the Authenticator app during warning or blocking phases. These screens are dismissible but indicate the device status.
Communicate to helpdesk staff that Authenticator will become unusable for Entra accounts on jailbroken or rooted devices. Update internal documentation if you reference Authenticator usage. No admin action is required to enable or configure this feature. Learn more: About Microsoft Authenticator | Microsoft Support [Compliance considerations] No compliance considerations identified, review as appropriate for your organization. https://support.microsoft.com/account-billing/about-microsoft-authenticator-9783c865-0308-42fb-a519-8cf666fe0acc |
| 2025-11-12 | MC MessageTagNames | Feature update, User impact, Admin impact | Updated message, Feature update, User impact, Admin impact |
| 2025-11-12 | MC Summary | Starting February 2026, Microsoft Authenticator will block Entra credentials on jailbroken/rooted iOS and Android devices through a phased rollout: warning, blocking, then wiping credentials. This security feature requires no admin setup. Users on compliant devices remain unaffected. Organizations should notify users and update documentation accordingly. | Starting February 2026, Microsoft Authenticator will detect jailbroken/rooted devices on iOS and Android, blocking and eventually wiping Entra credentials on such devices in a phased rollout through April 2026. This security feature is automatic, affects only compromised devices, and requires no admin configuration. |
| 2025-11-12 | MC Last Updated | 10/25/2025 00:09:11 | 2025-11-11T21:33:49Z |
| 2025-11-12 | MC Messages | [Introduction]
Starting February 2026, we will introduce jailbreak and root detection for Entra credentials in the Microsoft Authenticator app on both iOS and Android platforms. This change enhances security by preventing Entra credentials from functioning on jailbroken/rooted devices. All existing Entra credentials on jailbroken or rooted devices will be wiped to protect your organization. This capability is secure by default and does not require any admin configuration or control. [When this will happen] General Availability (Worldwide) rollout begins in February 2026 and is expected to complete in April 2026. | Updated November 11, 2025: We have updated the content and the images below. Thank you for your patience.
[Introduction] Starting February 2026, we will introduce jailbreak and root detection for Entra credentials in the Microsoft Authenticator app on both iOS and Android platforms. This change enhances security by preventing Entra credentials from functioning on jailbroken/rooted devices. All existing Entra credentials on jailbroken or rooted devices will be wiped to protect your organization. This capability is secure by default and does not require any admin configuration or control. [When this will happen] General Availability (Worldwide) rollout begins in February 2026 and is expected to complete in April 2026. |
| 2025-11-12 | MC Title | Microsoft Authenticator app: Upcoming changes to jailbreak and root detection | (Updated) Microsoft Authenticator app: Upcoming changes to jailbreak and root detection |
| 2025-11-12 | MC How Affect | Who is affected: All users of Microsoft Authenticator on iOS and Android whose Entra credentials are registered on jailbroken or rooted device.
What will happen: The feature is secure by default. Users on jailbroken or rooted devices will experience the following phased rollout: Phase 1 - Warning Mode: Users receive a warning that their device is jailbroken or rooted and will be blocked in the future (screenshots 1-4): Phase 2 - Blocking Mode: Users are blocked from registering Entra credentials or signing in via Authenticator (screenshots 5-6): Phase 3 - Wipe Mode: Existing Entra credentials are wiped from jailbroken or rooted devices (screenshots 7-10): Users on compliant (non-Jailbroken or non-rooted) devices will not be affected. | Who is affected: All users of Microsoft Authenticator on iOS and Android whose Entra credentials are registered on jailbroken or rooted device. This is going to be a continuous check.
What will happen: The feature is secure by default and enabled to all customers. There is no opt-out capability.. Users on jailbroken or rooted devices will experience the following phased rollout. An estimated gap between 3 phases is ~ 1 month. Phase 1 - Warning Mode: Users receive a warning that their device is jailbroken or rooted and will be blocked in the future (screenshots 1-4): Phase 2 - Blocking Mode: Users are blocked from registering Entra credentials or signing in via Authenticator (screenshots 5-8): Phase 3 - Wipe Mode: Existing Entra credentials are wiped from jailbroken or rooted devices (screenshots 9-11): Users on non-Jailbroken or non-rooted devices will not be affected. |
Last updated 2 months ago ago