Is Microsoft Authenticator Safe | Transmit Security (2024)

  • Platform
  • About
  • Resources
    • Is Microsoft Authenticator Safe | Transmit Security (3)

      Featured Blog Post:

      How Fraudsters Are Targeting Digital Businesses Across All Industries — And What You Can Do About It

      Historically, banks and financial institutions were the primary targets for fraudsters. However, as digital channels become more prevalent, diverse customer-facing applications such as airlines, travel platforms, telcos and digital...

      Learn more

      Media

      Transmit Security is making headlines. Read the latest in the news.

      Identity Hub

      Start here to get the CIAM basics. This glossary-style blog slices through the noise to give you clarity.

      Blog

      Get best practices, industry insights, thought leadership and the latest on CIAM innovations.

      System Status

      Check our system status.

      Events & Webinars

      Join us in person at conferences or stream webinars on hot CIAM topics.

      Support

      Existing customer? Find the help you need or contact our experts.

      Content Hub

      Take a deeper dive into the world of CIAM. Explore analyst reports, white papers, survey data and customer stories.

  • |
  • Developers
  • Platform
  • About
    • About
    • Contact Us
    • Media
    • Leadership
    • Careers
    • Become a Partner
    • Corporate Social Responsibility
  • Resources
  • Developers

Request a Demo

By clicking the button, you agree to the Terms and Conditions

Click Here to Read Transmit Security Privacy Policy

Request a Demo

Back to blogs

Get the Transmit Security Blog Straight To Your Email

By clicking the button, you agree to the Terms and Conditions

Click Here to Read Transmit Security Privacy Policy

Subscribe

Table of Contents

by Alex Brown

Microsoft Authenticator: A False Sense of Security?

As a naturally curious security professional, I am constantly trying out new security services. I decided to enable the Microsoft Authenticator on my personal Microsoft account. Microsoft describes their Authenticator as “More secure. Passwords can be forgotten, stolen, or compromised. With Authenticator, your phone provides an extra layer of security on top of your PIN or fingerprint.”

Almost all digital transformation projects include applications that authenticate users and protect sensitive data, as well as integrating services across multiple channels. Passwords are not secure, as recent data leaks and hacks have shown. Authenticator Apps arose as a result of the need for more secure methods using multi-factor authentication. Google authenticator and Microsoft authenticator are among the top authenticator apps used.

I downloaded the Microsoft Authenticator app and added my personal Microsoft account to it. The app asked for my Microsoft password and email verification code. Note that both of these are vulnerable to a simple phishing attack. I completed the registration process and logged into my account several times using the Authenticator app to verify that it worked. It did. I could log into my account without a password.

Is Microsoft Authenticator Safe | Transmit Security (5)

Can two users log into Microsoft Authenticator at the same time?

My assumption, after enabling the app, was that no one else could log into my account without me approving it first through the Authenticator app. It goes without saying that no one should be able to register another Authenticator app on my behalf without me approving it first with the Authenticator app that I already have.

So I asked a friend to try to add my personal Microsoft account to his Microsoft Authenticator app. After he entered my email address I got a push notification on my mobile device. I opened the push notification on my device and selected “Deny” to deny him from continuing. But my friend was faster and selected “use password instead” on his phone moments before I selected “Deny”. My friend was then able to enter my password and email verification code and successfully register his Microsoft Authenticator using my account. Microsoft completely ignored me pushing the Deny button and didn’t provide any feedback that a new Authenticator app was registered on my behalf. Microsoft Authenticator would not prevent a criminal from accessing an account once they have obtained a username and password.

After this experiment we were both able to log into my account, each with our own phones. But what happens if one of us chooses Allow and the other chooses Deny? Apparently first to click wins. If the attacker tries to log in and clicks Approve first, the victim can click Deny but it won’t matter – the attacker will get in and once again – no indication is sent to the victim that someone got in.

DoesMicrosoft Authenticator have an extra security layer?

Where was the extra layer of security that Microsoft Authenticator claimed? While the Microsoft Authenticator app was easy enough to use (as any Authenticator App), is it simply providing a false sense of security?

Using biometrics and push notifications for security purposes should incorporate many additional layers of security resulting in a dynamic, risk-based approach to authentication and authorization. The best systems carefully assess and correlate a host of indicators and variables from the device and the session in real time to validate the user and revalidate if necessary. In the examples above there were plenty of red flags that should have generated alerts and blocked the imposter before access was provided to the device. If you’re serious about device and system security, continuous adaptive risk should be a foundation to your organization’s IT security infrastructure.

An update on ‘Is Microsoft Authenticator Safe?’

Update: I received a few comments on whether 2FA was enabled or not in my tests above. This is not the point I was trying to make here. Even when 2FA is enabled, attackers can still choose to use Email or SMS as a second factor instead of the Microsoft Authentication App. Both Email and SMS are much weaker in terms of security. I’ll follow up next week with a post explaining how SMS and Email 2FA can be bypassed. My expectation is that once I enable an Authenticator App, attackers should not have an easy way of using SMS or Email instead to login or register another Authenticator App.

  • Is Microsoft Authenticator Safe | Transmit Security (6)

    Alex Brown

    A self-professed technology geek, content writer Alex Brown is the kind of person who actually reads the manual that comes with his smartphone from cover to cover. His experience evangelizing for the latest and greatest tech solutions gives him an energized perspective on the latest trends in the authentication industry. Alex most recently led the content team at Boston-based tech company Form.com.

    View all posts

Get the Transmit Security Blog Straight To Your Email

By clicking the button, you agree to the Terms and Conditions

Click Here to Read Transmit Security Privacy Policy

Subscribe

Latest blog posts

How Fraudsters Are Targeting Digital Businesses Across All Industries — And What You Can Do About It

Read now

Demystifying Crypto-Binding: Enhancing Security with Transmit Security’s Web Crypto for Device ID

Read now

Read now

Read now

Is Microsoft Authenticator Safe | Transmit Security (2024)
Top Articles
Cash App Security and Safety
Current Studies | Veros Health
Cranes For Sale in United States| IronPlanet
Average Jonas Wife
Ret Paladin Phase 2 Bis Wotlk
Comcast Xfinity Outage in Kipton, Ohio
Toyota gebraucht kaufen in tacoma_ - AutoScout24
Emmalangevin Fanhouse Leak
Osrs But Damage
Deshret's Spirit
Jessica Renee Johnson Update 2023
Purple Crip Strain Leafly
Craigslist Cars Nwi
2021 Lexus IS for sale - Richardson, TX - craigslist
Slope Tyrones Unblocked Games
History of Osceola County
Khiara Keating: Manchester City and England goalkeeper convinced WSL silverware is on the horizon
Missed Connections Dayton Ohio
Lcwc 911 Live Incident List Live Status
Buy Swap Sell Dirt Late Model
Race Karts For Sale Near Me
Full Standard Operating Guideline Manual | Springfield, MO
Katie Sigmond Hot Pics
Free Personals Like Craigslist Nh
Sand Dollar Restaurant Anna Maria Island
Anonib Oviedo
Rgb Bird Flop
Sacramento Craigslist Cars And Trucks - By Owner
Bfri Forum
Gideon Nicole Riddley Read Online Free
Haley Gifts :: Stardew Valley
John F Slater Funeral Home Brentwood
Acadis Portal Missouri
Tirage Rapid Georgia
The Transformation Of Vanessa Ray From Childhood To Blue Bloods - Looper
Ksu Sturgis Library
Pepsi Collaboration
Miracle Shoes Ff6
Craigs List Palm Springs
Emily Tosta Butt
Sarahbustani Boobs
Courses In Touch
Craigslist Com St Cloud Mn
Iupui Course Search
Interminable Rooms
Caphras Calculator
Gonzalo Lira Net Worth
Abigail Cordova Murder
Game Like Tales Of Androgyny
Nfhs Network On Direct Tv
Ocean County Mugshots
Anthony Weary Obituary Erie Pa
Latest Posts
Article information

Author: Merrill Bechtelar CPA

Last Updated:

Views: 5617

Rating: 5 / 5 (70 voted)

Reviews: 85% of readers found this page helpful

Author information

Name: Merrill Bechtelar CPA

Birthday: 1996-05-19

Address: Apt. 114 873 White Lodge, Libbyfurt, CA 93006

Phone: +5983010455207

Job: Legacy Representative

Hobby: Blacksmithing, Urban exploration, Sudoku, Slacklining, Creative writing, Community, Letterboxing

Introduction: My name is Merrill Bechtelar CPA, I am a clean, agreeable, glorious, magnificent, witty, enchanting, comfortable person who loves writing and wants to share my knowledge and understanding with you.