← Back
(Updated) Microsoft Authenticator app: Upcoming changes to jailbreak and root detection
MC1179154 · build prod-20251231-200323
Category
planForChange
Severity
normal
Major change
False
Last modified
2026-02-24 21:53:25
Summary source
Azure OpenAI (gpt-4.1)
Action by (Graph)
Action by (AI)
2026-02-01 00:00:00
Services
Microsoft Entra
Tags
Updated message, Feature update, User impact, Admin impact
Master tags
User, Admin, Security
Roadmap IDs

One-line summary

Microsoft Authenticator will block and wipe Entra credentials from jailbroken/rooted iOS and Android devices, with phased rollout starting late February 2026 for Android and April for iOS.

Similar updates

More like this
MC1024404 (Updated) Microsoft Entra: Browser access will be enabled by default for all Android users
(Updated) Microsoft Entra: Browser access will be enabled by default for all Android users Microsoft Entra ID device registration for Android will become hardware-bound, retiring the Enable Browser Access feature in Authenticator and Company Portal apps; change is automatic. The Enable Browser Access feature will retire from the Company Portal.
MC1184994 (Updated) Microsoft Teams frontline BYOD onboarding wizard
(Updated) Microsoft Teams frontline BYOD onboarding wizard Microsoft is launching a dynamic web onboarding wizard for Teams BYOD, simplifying setup for frontline workers on Android/iOS with MFA support; public preview rolls out from Nov 2025. Updated March 23, 2026: We have updated the timeline. [Introduction] To support frontline workers using.
MC1191924 Microsoft Entra ID: Enhance protection of the authentication experience by blocking external script injection
Microsoft Entra ID: Enhance protection of the authentication experience by blocking external script injection Microsoft Entra ID sign-in will enforce a stricter Content Security Policy, blocking non-Microsoft scripts and injected code, starting rollout in October 2026 to enhance security against XSS threats. Introduction As part of Microsoft’s .
MC1088732 Microsoft Teams: Important updates for Android-based Teams devices – Authentication changes coming soon
Microsoft Teams: Important updates for Android-based Teams devices – Authentication changes coming soon Teams Android devices must update to specified app versions for modern Entra ID authentication by Dec 31, 2025, or risk service disruption; enhanced security features will be enabled. If your organization does not manage one or more certified.
MC1097225 (Updated) Entra ID: Upcoming changes to support passkey profiles in the authentication methods policy (preview)
(Updated) Entra ID: Upcoming changes to support passkey profiles in the authentication methods policy (preview) Entra ID expands passkey policy in November 2025 public preview, enabling group-based passkey controls, new API schema, and broader attestation support for FIDO2/passkey providers. Updated November 5, 2025: We have updated the timeline.
MC1163756 Outlook for Android will require Android 10.0 or higher starting January 2026
Outlook for Android will require Android 10.0 or higher starting January 2026 Outlook for Android will require Android 10.0+ starting January 5, 2026; devices on Android 9.x or below will stop receiving updates and support. [Introduction] To maintain app performance, security, and compatibility across devices, Outlook for Android will no longer.

Details

Summary
Starting late February 2026, Microsoft Authenticator will detect jailbroken/rooted devices on iOS and Android, blocking Entra credentials on such devices through phased warnings, blocking, and credential wiping. This security feature is automatic with no opt-out. Users on non-jailbroken/rooted devices are unaffected. Notify users and helpdesk accordingly.

Body (from Message Center)

Updated February 24, 2026: We have updated the timeline. Thank you for your patience.

[Introduction]

Starting end of February 2026, we will introduce jailbreak and root detection for Entra credentials in the Microsoft Authenticator app on both iOS and Android platforms. This change enhances security by preventing Entra credentials from functioning on jailbroken/rooted devices. All existing Entra credentials on jailbroken or rooted devices will be wiped to protect your organization. This capability is secure by default and does not require any admin configuration or control.

[When this will happen] 

General Availability (Worldwide Android) rollout begins in end of February 2026 and is expected to complete in mid-year 2026 (previously April).

General Availability (Worldwide iOS) rollout begins in April 2026 (previously March) and is expected to complete in mid-year 2026 (previously April).

[How this affects your organization]

Who is affected: All users of Microsoft Authenticator on iOS and Android whose Entra credentials are registered on jailbroken or rooted device. This is going to be a continuous check.

What will happen:

  • The feature is secure by default and enabled to all customers. There is no opt-out capability..
  • Users on jailbroken or rooted devices will experience the following phased rollout. An estimated gap between 3 phases is ~ 1 month.
    • Phase 1 – Warning Mode: Users receive a warning that their device is jailbroken or rooted and will be blocked in the future (screenshots 1-4): 
    • user settings

      user settings

      user settings

      user settings

    • Phase 2 – Blocking Mode: Users are blocked from registering Entra credentials or signing in via Authenticator (screenshots 5-8):
    • user settings

      user settings

      user settings

      user settings

    • Phase 3 – Wipe Mode: Existing Entra credentials are wiped from jailbroken or rooted devices (screenshots 9-11):
    • user settings

      user settings

      user settings

  • Users on non-Jailbroken or non-rooted devices will not be affected.

[What you can do to prepare]

  • Notify users about this upcoming change. Users will see error messages or banners in the Authenticator app during warning or blocking phases. These screens are dismissible but indicate the device status.
  • Communicate to helpdesk staff that Authenticator will become unusable for Entra accounts on jailbroken or rooted devices.
  • Update internal documentation if you reference Authenticator usage.
  • No admin action is required to enable or configure this feature.

Learn more: About Microsoft Authenticator | Microsoft Support

[Compliance considerations]

No compliance considerations identified, review as appropriate for your organization.

Raw JSON (for debugging)

Expand/collapse the full payload below.
Show/hide raw
{
  "snapshot_item": {
    "action_required_by": null,
    "ai_action_required_by": "2026-02-01T00:00:00Z",
    "ai_actions": [
      "Notify users about app restrictions on jailbroken/rooted devices",
      "Update helpdesk and internal documentation"
    ],
    "ai_master_tags": [
      "User",
      "Admin",
      "Security"
    ],
    "ai_model": "gpt-4.1",
    "ai_summary": "Microsoft Authenticator will block and wipe Entra credentials from jailbroken/rooted iOS and Android devices, with phased rollout starting late February 2026 for Android and April for iOS.",
    "ai_topics": [
      "Entra",
      "Authenticator"
    ],
    "category": "planForChange",
    "details_map": {
      "Summary": "Starting late February 2026, Microsoft Authenticator will detect jailbroken/rooted devices on iOS and Android, blocking Entra credentials on such devices through phased warnings, blocking, and credential wiping. This security feature is automatic with no opt-out. Users on non-jailbroken/rooted devices are unaffected. Notify users and helpdesk accordingly."
    },
    "id": "MC1179154",
    "importance": 4,
    "is_major_change": false,
    "last_modified": "2026-02-24T21:53:25Z",
    "ms_products": [
      "Entra"
    ],
    "platforms": null,
    "roadmap_ids": [],
    "services": [
      "Microsoft Entra"
    ],
    "severity": "normal",
    "tags": [
      "Updated message",
      "Feature update",
      "User impact",
      "Admin impact"
    ],
    "title": "(Updated) Microsoft Authenticator app: Upcoming changes to jailbreak and root detection"
  }
}