Azure/entra admins - MS Authenticator question?

We are a Microsoft campus, we are being pushed to us MS Authenticator app on our personal phones… Now I’m digging in to find facts on the online rumors.

App permissions say it needs approximate and specific location data. Online rumors say you can see the location of your employees at any time day or night from the admin control panel. I don’t have access to that area, so I’m asking if this is true.

To get around my policy of not installing work stuff on my personal equipment, I’m going to buy a cheap phone and just use WiFi for the MS auth. But I’d really like to know if it is possible to track users with this app.

Thanks.

I updated the app today to the latest version and I don’t need to enable location services. I am on iOS 26.6.1

1 Like

IOS is different since Apple blocks this by default, MS bent a knee to apple users. Android still says it requires location services and prefers the more accurate precise location.

I just do not trust MS on my phone, bad enough the other garbage they run on computers. But the possibility that work can see where I am at any given time is too far.

The default is to use your IP for location and, as I’m sure you are aware, is not exactly accurate. This is recorded from any device you login from, so not authenticator specific. It is possible to have GPS based access controls which will of course be more accurate and that does require the authenticator app, but you still have to give it access. See here for details

Where I currently work we don’t use GPS or network based locations. We only allow access from authorised and compliant devices. However, we don’t have people traveling to, shall we say, sensitive countries, and I can see where GPS based access might be appropriate.

Edit: For users that we encounter who don’t want to use the authenticator app we provide Yubikeys. More secure and obviously can’t be tracked. Maybe see if they will let you use one. Often the authenticator app requirement is purely because it is the easiest secure option.

1 Like

I have an OnlyKey with 6 buttons that I bought to test with. Guidance coming out suggests this as one of the better ways, Microsoft is removing sms codes due to security concerns with SIM duplication. Not sure if that sms removal is only restricted to admins, or for all users.

SMS and voice approval are being retired for all accounts as they are not considered secure.

I was wondering about that. I bet they use the lack of security to force the authenticator app, and then increase the permissions required to make it work so they can collect more data. While many will say, never happen, just wait for it, the slow march to every keystroke, and every movement tracked is progressing.

It does leave the KaiOS cheap BLU branded phones out of the loop, and Graphene is going to be a problem now that Motorola is backing the project and probably releasing phones with Graphene in the near future.

If the cheapo BLU flip phones had the authenticator app, I’d buy one just for this purpose. Run it wifi only and just not care. I may need to go with a FIDO2 key after this happens, but going to drag my feet to make a point.

Why does Microsoft Authenticator ask me to grant permission to access my location?

You’ll see a prompt from Authenticator asking for access to your location if your IT admin has created a policy requiring you to share your GPS location before you are allowed to access specific resources. You’ll need to share your location once every hour to ensure you’re still within a country where you are allowed to access the resource.

On iOS, Microsoft recommends allowing the app to access location always. Follow the iOS prompts to grant that permission. Here’s what each permission level will mean for you:

  • Allow while using the app: If you choose this option, you’ll be prompted to select two more options.
  • Always allow (recommended): While you’re still accessing the protected resource, for the next 24 hours, your location will be shared silently once per hour from the device, so you won’t need to get out your phone and manually approve each hour.
  • Keep only while using: While you’re still accessing the protected resource, every hour, you’ll need to pull out your device and manually approve the request.
  • Allow once: Once every hour that you’re still accessing the resource, or next time you try to access the resource, you’ll need to grant permission again. You will need to go to Settings and manually enable the permission.
  • Don’t allow: If you select this option, you’ll be blocked from accessing the resource. If you change your mind, you’ll need to go to Settings and manually enable the permission.

On Android, Microsoft recommends allowing the app to access location all the time. Follow the Android prompts to grant that permission. Here’s what each permission level will mean for you:

  • Allow all the time (recommended): While you’re still accessing the protected resource, for the next 24 hours, your location will be shared silently once per hour from the device, so you will not need to get out your phone and manually approve each hour.
  • Allow only while using the app: While you’re still accessing the protected resource, every hour, you’ll need to pull out your device and manually approve the request.
  • Deny and don’t ask again: If you select this option, you’ll be blocked from accessing the resource.

How is my location information used and stored by Microsoft Authenticator?

Authenticator collects your GPS information to determine what country you’re located in. The country name and location coordinates are sent back to the system to determine if you are allowed to access the protected resource. The country name is stored and reported back to your IT admin (if applicable), but your actual coordinates are never saved or stored on Microsoft servers.

So says Microsoft, but do we really trust that they are not storing Lat/Long data to make a map of where we are? It suggests that it only does this while using microsoft products/services, but still skeptical.

Not clear from the post, do you actually need to use MS authenticator? Is it part of your work requirement?

Yes, we are all going to be required to use a more secure method of accessing Microsoft products, for my work, they are pushing authenticator on everyone.