this post was submitted on 05 Jan 2024
480 points (98.2% liked)

Memes

45132 readers
3258 users here now

Rules:

  1. Be civil and nice.
  2. Try not to excessively repost, as a rule of thumb, wait at least 2 months to do it if you have to.

founded 5 years ago
MODERATORS
 
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 24 points 8 months ago (6 children)

PSA, don't use Microsoft authenticator. It's easy to accidentally wipe your cloud backup and lose all your authenticator codes when switching devices

[–] [email protected] 10 points 8 months ago (1 children)
[–] [email protected] 3 points 8 months ago (1 children)

I think you can use standard TOTP regardless if you add TOTP as an option in the authentication methods on your account page. At least I did and the system has yet to complain.

[–] [email protected] 2 points 8 months ago

Nope, IT can disable third-party TOTP services, and force all employees to use the official MS Authenticator app.

[–] [email protected] 7 points 8 months ago* (last edited 8 months ago) (1 children)

Is there actually any way to export the secrets from MS authenticator? I've been wanting to move them to something like bitwarden but it's gonna take ages if I have to reset all ~50

[–] [email protected] 3 points 8 months ago (1 children)

They provide "Cloud Backups".

Take the time, move them 5 a day. Better than loosing them forever

[–] [email protected] 1 points 8 months ago

Yeah I suppose that's the best solution, I'm just a little impatient lol

[–] [email protected] 2 points 8 months ago

Don't worry, I'm going to keep using Bitwarden for my personal accounts.

[–] [email protected] 2 points 8 months ago (1 children)

Yes, and while you can move it phone to phone on iOS, you cannot on Android. So stupid.

If you are forced to use it by your company just use it for that email, nothing else. Use something like authy instead.

[–] [email protected] 1 points 8 months ago

If your company forced you to use mobile authentication, they should also be providing you with a device on the company plan at no cost to the employee.

In which case you should absolutely use MS Auth and give them all your delicious work data because nothing personal should be on the device anyway.

[–] [email protected] 1 points 8 months ago

Learnt that the hard way

[–] [email protected] 1 points 8 months ago

Somehow I don't think there's much risk of anyone doing it willingly...