0 points

Same thing with proton pass. How will i login to proton pass if i save my proton mail password in it.

permalink
report
reply
7 points

Why would you store your password manager’s password in your password manager??? That’s like putting a safe’s key into the safe

permalink
report
parent
reply
1 point

I know but I remember it was saved by default in it. I am really confused about it. What should I do abt it? Should I just make a memorable password and remember the proton account password? or something else?

permalink
report
parent
reply
1 point
*

Yes, use random words or sentences. https://www.useapassphrase.com/

permalink
report
parent
reply
11 points

Anyone else hate Microsoft forcing you to use Authenticator rather than alternatives?

Just another way I’m forced to install Microsoft crap on my devices :/

permalink
report
reply
8 points

I have 2FA through Authy on my Microsoft account.

permalink
report
parent
reply
7 points

You can work around it to use your own 2FA app.
Did it with my O365 account.

permalink
report
parent
reply
11 points

It’s been a long time since I set it up, but I have Microsoft accounts in my usual TOTP app (Aegis). Maybe I did it manually? But it’s definitely possible.

permalink
report
parent
reply
3 points

Not if your organization disables alternative TOTP apps 😔.

permalink
report
parent
reply
4 points

Is it a default setting?
If no, our admin didnt enable it and I could do it.

permalink
report
parent
reply
36 points

PSA, don’t use Microsoft authenticator. It’s easy to accidentally wipe your cloud backup and lose all your authenticator codes when switching devices

permalink
report
reply
11 points

Cooperate forces me.

permalink
report
parent
reply
5 points

I think you can use standard TOTP regardless if you add TOTP as an option in the authentication methods on your account page. At least I did and the system has yet to complain.

permalink
report
parent
reply
4 points

Nope, IT can disable third-party TOTP services, and force all employees to use the official MS Authenticator app.

permalink
report
parent
reply
1 point

Learnt that the hard way

permalink
report
parent
reply
3 points

Don’t worry, I’m going to keep using Bitwarden for my personal accounts.

permalink
report
parent
reply
9 points
*

Is there actually any way to export the secrets from MS authenticator? I’ve been wanting to move them to something like bitwarden but it’s gonna take ages if I have to reset all ~50

permalink
report
parent
reply
3 points

They provide “Cloud Backups”.

Take the time, move them 5 a day. Better than loosing them forever

permalink
report
parent
reply
1 point

Yeah I suppose that’s the best solution, I’m just a little impatient lol

permalink
report
parent
reply
3 points

Yes, and while you can move it phone to phone on iOS, you cannot on Android. So stupid.

If you are forced to use it by your company just use it for that email, nothing else. Use something like authy instead.

permalink
report
parent
reply
3 points

If your company forced you to use mobile authentication, they should also be providing you with a device on the company plan at no cost to the employee.

In which case you should absolutely use MS Auth and give them all your delicious work data because nothing personal should be on the device anyway.

permalink
report
parent
reply
2 points

Authy requires a phone number last I checked & is a part of a for-profit entity. TOTP management is a simple task so there is no reason not to be using something open source.

permalink
report
parent
reply
1 point

Somehow I don’t think there’s much risk of anyone doing it willingly…

permalink
report
parent
reply
4 points

Can you provide more info how it’s easy to accidentally wipe? I’ve only done a transfer once, but it was by installing authenticator on the new phone and logging in, then deleting the other one on the old phone after testing that the codes work.

permalink
report
parent
reply
8 points

You have to begin the recovery on the new device before logging in. If you log in normally and enable cloud backup on the new device, it will simply overwrite the existing backup with a new empty one

permalink
report
parent
reply
4 points

That design is awful

permalink
report
parent
reply
6 points

This is a configuration item. Nothing to do with the app. It’s a choice your company has made.

permalink
report
reply
2 points

Interesting, do you happen to know which configuration item causes this?

permalink
report
parent
reply
2 points

The one that forces you only to use ‘passwordless’ logins or forces that MFA challenge. Your admins had a choice on what they allow.

permalink
report
parent
reply
1 point

It seems something changed on MS end though because I have control of what MFA i use on our corporate acxount, which was setup with Yubikey, until about a month ago when this Use Your Outlook Mobile started on it’s own

permalink
report
parent
reply
2 points

My admins said they see a big red “insecure” banner if they allow other 2FA apps.

permalink
report
parent
reply
-1 points

I mean, unless your service lets you pick individually that usually means turning on SMS. That’s probably why they have a general policy, it’s a pain in the ass to manage multiples.

permalink
report
parent
reply
16 points

I got FreeOTP from F-droid. Works like a charm.

permalink
report
reply
10 points

I usually use Bitwarden myself, but the company uses Microsoft Authenticator.

permalink
report
parent
reply
5 points

I feel your pain

permalink
report
parent
reply
2 points

I use it for all of my work accounts. When it gives me troubles, I put my feet up.

permalink
report
parent
reply
3 points

I recommend Aegis, but I guess it’s a matter of taste

permalink
report
parent
reply
1 point

Isn’t that discontinued? I just installed aegis from fdroid

permalink
report
parent
reply
22 points

Aegis here

permalink
report
parent
reply
4 points

Secur user checking in

permalink
report
parent
reply

Memes

!memes@lemmy.ml

Create post

Rules:

  1. Be civil and nice.
  2. Try not to excessively repost, as a rule of thumb, wait at least 2 months to do it if you have to.

Community stats

  • 8K

    Monthly active users

  • 13K

    Posts

  • 288K

    Comments