Microsoft Authenticator Will Remove Work Entra Credentials on Compromised Phones

Close-up view of a person’s hand holding a smartphone, with the device’s camera lens visible and illuminated by a blue light, suggesting the use of facial recognition or biometric scanning technology on the mobile device against a blurred, colorful background.

Microsoft is tightening mobile sign-in security: its Authenticator app will automatically purge work or school Microsoft Entra credentials from any device it detects as jailbroken or rooted. The change is designed to close off attacks that exploit compromised phones to hijack multi‑factor authentication sessions.

Rooting and jailbreaking grant deep control over iOS and Android at the cost of built‑in protections. Under Microsoft’s approach, Authenticator periodically checks device integrity; if the phone fails that check, enterprise Entra accounts stored in the app are removed immediately—no special admin policy required. The safeguard applies across iPhone and Android devices.

For organizations, the impact is straightforward: employees using modified devices will find their corporate accounts disappear from Authenticator, and helpdesks may need to steer those users to compliant devices or managed handsets. The move aligns with Zero Trust principles by treating device health as a first‑class signal alongside user identity and context.

Personal Microsoft accounts and non‑Microsoft one‑time‑password entries inside Authenticator are unaffected. The change targets only work or school Entra credentials, balancing enterprise risk controls with personal use on the same handset.

Sources: Microsoft Support

By the ID Tech Editorial Team