MC1179154 – (Updated) Microsoft Authenticator app: Upcoming changes to jailbreak and root detection

cloudscout.one Icon

check before: 2026-02-01

Product:

Entra

Platform:

Android, iOS, Online, World tenant

Status:

Change type:

Admin impact, Feature update, Updated message, User impact

Links:

Details:

Summary:
Starting February 2026, Microsoft Authenticator will detect jailbroken/rooted devices on iOS and Android, blocking and eventually wiping Entra credentials on such devices in a phased rollout through April 2026. This security feature is automatic, affects only compromised devices, and requires no admin configuration.

Details:
Updated November 11, 2025: We have updated the content and the images below. Thank you for your patience.
[Introduction]
Starting February 2026, we will introduce jailbreak and root detection for Entra credentials in the Microsoft Authenticator app on both iOS and Android platforms. This change enhances security by preventing Entra credentials from functioning on jailbroken/rooted devices. All existing Entra credentials on jailbroken or rooted devices will be wiped to protect your organization. This capability is secure by default and does not require any admin configuration or control.
[When this will happen]
General Availability (Worldwide) rollout begins in February 2026 and is expected to complete in April 2026.

Change Category:
XXXXXXX ... free basic plan only

Scope:
XXXXXXX ... free basic plan only

Release Phase:

Created:
2025-10-25

updated:
2025-11-12

Task Type

XXXXXXX ... free basic plan only

Docu to Check

XXXXXXX ... free basic plan only

MS How does it affect me

XXXXXXX ... free basic plan only

MS Preperations

XXXXXXX ... free basic plan only

MS Urgency

XXXXXXX ... free basic plan only

MS workload name

XXXXXXX ... free basic plan only

Pictures

XXXXXXX ... free basic plan only

summary for non-techies**

XXXXXXX ... free basic plan only

Direct effects for Operations**

Device Compatibility Issues
Users with jailbroken or rooted devices will be blocked from accessing Entra credentials, leading to potential loss of access to critical applications and services.
   - roles: End Users, Helpdesk Staff
   - references: https://support.microsoft.com/account-billing/about-microsoft-authenticator-9783c865-0308-42fb-a519-8cf666fe0acc

User Experience Disruption
Users will receive warnings and error messages during the phased rollout, causing confusion and frustration among those unaware of the changes.
   - roles: End Users, IT Support
   - references: https://support.microsoft.com/account-billing/about-microsoft-authenticator-9783c865-0308-42fb-a519-8cf666fe0acc

Increased Helpdesk Inquiries
The rollout will likely lead to an increase in helpdesk inquiries as users seek assistance regarding access issues and error messages related to their devices.
   - roles: Helpdesk Staff, IT Support
   - references: https://support.microsoft.com/account-billing/about-microsoft-authenticator-9783c865-0308-42fb-a519-8cf666fe0acc

Loss of Data Access
Existing Entra credentials will be wiped from jailbroken or rooted devices, resulting in potential data loss for users who do not have backups.
   - roles: End Users, Data Managers
   - references: https://support.microsoft.com/account-billing/about-microsoft-authenticator-9783c865-0308-42fb-a519-8cf666fe0acc

Documentation Updates Required
Internal documentation referencing the use of Microsoft Authenticator will need to be updated to reflect the new security measures, requiring time and resources.
   - roles: IT Documentation Team, Compliance Officers
   - references: https://support.microsoft.com/account-billing/about-microsoft-authenticator-9783c865-0308-42fb-a519-8cf666fe0acc

Configutation Options**

XXXXXXX ... paid membership only

Opportunities**

User Education and Communication
With the upcoming changes in the Microsoft Authenticator app, there is an opportunity to enhance user education regarding device security. Providing clear communication about the implications of using jailbroken or rooted devices can improve user experience and compliance with security policies.
   - next-steps: Develop a communication plan that includes emails, webinars, and training sessions to inform users about the changes and the importance of device security. Create easy-to-understand materials that explain how to check if their device is jailbroken/rooted and the steps to take if it is.
   - roles: IT Support, Security Team, Training Coordinators
   - references: https://support.microsoft.com/account-billing/about-microsoft-authenticator-9783c865-0308-42fb-a519-8cf666fe0acc

Helpdesk Preparedness
As the Authenticator app becomes unusable for users with jailbroken or rooted devices, preparing the helpdesk staff to handle user inquiries and support requests will enhance operational efficiency and user satisfaction.
   - next-steps: Conduct training sessions for helpdesk staff to familiarize them with the changes, potential user issues, and troubleshooting steps. Create a knowledge base article to help staff respond to common questions related to the new feature.
   - roles: Helpdesk Staff, IT Support Managers
   - references: https://support.microsoft.com/account-billing/about-microsoft-authenticator-9783c865-0308-42fb-a519-8cf666fe0acc

Internal Documentation Update
Updating internal documentation regarding the use of Microsoft Authenticator and the new security measures will ensure that all employees are informed and aligned with the new protocols, improving overall compliance and security posture.
   - next-steps: Review and revise all internal documentation related to Microsoft Authenticator, ensuring it reflects the upcoming changes. Distribute the updated documentation to all relevant stakeholders and ensure it is accessible in internal resources.
   - roles: IT Administrators, Compliance Officers
   - references: https://support.microsoft.com/account-billing/about-microsoft-authenticator-9783c865-0308-42fb-a519-8cf666fe0acc

Potentional Risks**

XXXXXXX ... paid membership only

IT Security**

XXXXXXX ... paid membership only

explanation for non-techies**

XXXXXXX ... free basic plan only

** AI generated content. This information must be reviewed before use.

a free basic plan is required to see more details. Sign up here


A cloudsocut.one plan is required to see all the changed details. If you are already a customer, choose login.
If you are new to cloudscout.one please choose a plan.



change history

DatePropertyoldnew
2025-11-12MC prepareNotify users about this upcoming change.
Communicate to helpdesk staff that Authenticator will become unusable for Entra accounts on jailbroken or rooted devices.
Update internal documentation if you reference Authenticator usage.
No admin action is required to enable or configure this feature.
Learn more: About Microsoft Authenticator | Microsoft Support
[Compliance considerations]
No compliance considerations identified, review as appropriate for your organization.
https://support.microsoft.com/account-billing/about-microsoft-authenticator-9783c865-0308-42fb-a519-8cf666fe0acc
Notify users about this upcoming change. Users will see error messages or banners in the Authenticator app during warning or blocking phases. These screens are dismissible but indicate the device status.
Communicate to helpdesk staff that Authenticator will become unusable for Entra accounts on jailbroken or rooted devices.
Update internal documentation if you reference Authenticator usage.
No admin action is required to enable or configure this feature.
Learn more: About Microsoft Authenticator | Microsoft Support
[Compliance considerations]
No compliance considerations identified, review as appropriate for your organization.
https://support.microsoft.com/account-billing/about-microsoft-authenticator-9783c865-0308-42fb-a519-8cf666fe0acc
2025-11-12MC MessageTagNamesFeature update, User impact, Admin impactUpdated message, Feature update, User impact, Admin impact
2025-11-12MC SummaryStarting February 2026, Microsoft Authenticator will block Entra credentials on jailbroken/rooted iOS and Android devices through a phased rollout: warning, blocking, then wiping credentials. This security feature requires no admin setup. Users on compliant devices remain unaffected. Organizations should notify users and update documentation accordingly.Starting February 2026, Microsoft Authenticator will detect jailbroken/rooted devices on iOS and Android, blocking and eventually wiping Entra credentials on such devices in a phased rollout through April 2026. This security feature is automatic, affects only compromised devices, and requires no admin configuration.
2025-11-12MC Last Updated10/25/2025 00:09:112025-11-11T21:33:49Z
2025-11-12MC Messages[Introduction]
Starting February 2026, we will introduce jailbreak and root detection for Entra credentials in the Microsoft Authenticator app on both iOS and Android platforms. This change enhances security by preventing Entra credentials from functioning on jailbroken/rooted devices. All existing Entra credentials on jailbroken or rooted devices will be wiped to protect your organization. This capability is secure by default and does not require any admin configuration or control.
[When this will happen]
General Availability (Worldwide) rollout begins in February 2026 and is expected to complete in April 2026.
Updated November 11, 2025: We have updated the content and the images below. Thank you for your patience.
[Introduction]
Starting February 2026, we will introduce jailbreak and root detection for Entra credentials in the Microsoft Authenticator app on both iOS and Android platforms. This change enhances security by preventing Entra credentials from functioning on jailbroken/rooted devices. All existing Entra credentials on jailbroken or rooted devices will be wiped to protect your organization. This capability is secure by default and does not require any admin configuration or control.
[When this will happen]
General Availability (Worldwide) rollout begins in February 2026 and is expected to complete in April 2026.
2025-11-12MC TitleMicrosoft Authenticator app: Upcoming changes to jailbreak and root detection(Updated) Microsoft Authenticator app: Upcoming changes to jailbreak and root detection
2025-11-12MC How AffectWho is affected: All users of Microsoft Authenticator on iOS and Android whose Entra credentials are registered on jailbroken or rooted device.
What will happen:
The feature is secure by default.
Users on jailbroken or rooted devices will experience the following phased rollout:
Phase 1 - Warning Mode: Users receive a warning that their device is jailbroken or rooted and will be blocked in the future (screenshots 1-4):




Phase 2 - Blocking Mode: Users are blocked from registering Entra credentials or signing in via Authenticator (screenshots 5-6):


Phase 3 - Wipe Mode: Existing Entra credentials are wiped from jailbroken or rooted devices (screenshots 7-10):




Users on compliant (non-Jailbroken or non-rooted) devices will not be affected.
Who is affected: All users of Microsoft Authenticator on iOS and Android whose Entra credentials are registered on jailbroken or rooted device. This is going to be a continuous check.
What will happen:
The feature is secure by default and enabled to all customers. There is no opt-out capability..
Users on jailbroken or rooted devices will experience the following phased rollout. An estimated gap between 3 phases is ~ 1 month.
Phase 1 - Warning Mode: Users receive a warning that their device is jailbroken or rooted and will be blocked in the future (screenshots 1-4):




Phase 2 - Blocking Mode: Users are blocked from registering Entra credentials or signing in via Authenticator (screenshots 5-8):




Phase 3 - Wipe Mode: Existing Entra credentials are wiped from jailbroken or rooted devices (screenshots 9-11):



Users on non-Jailbroken or non-rooted devices will not be affected.

Last updated 2 months ago ago

Leave a Reply

Share to MS Teams

Login to your account

Welcome Back, We Missed You!