However, some apps that I need for work, like Microsoft Authenticator, no longer work under GrapheneOS.
https://www.theregister.com/on-prem/2026/03/10/microsoft-tig...
However, some apps that I need for work, like Microsoft Authenticator, no longer work under GrapheneOS.
https://www.theregister.com/on-prem/2026/03/10/microsoft-tig...
Compliance =!= Security
You want me to have email and teams/slack on my phone? Sorry, I won't install the spyware. Want to pay for me to have a second phone with it? Okay. No? Well then, I just won't have email on my phone.
It needs to be made illegal imo. The company should provide you a device if you need one for the job.
What do you think is invasive in an MDM profile? It's just a channel to push data to your phone. Your information outside the work container stays private. Even inside the work container nobody can actually fetch any data from those apps.
I do agree with you though - a company must provide phones to their employees, not force them to enroll into their MDM services. The latter should be only for exceptional cases, e.g., gain temporarily access to corporate VPN, WiFi, etc., on your private device.
Scenario: Your account gets compromised somehow. It's signed in to your personal phone. Company data gets leaked or ransomed.
Your phone and its contents are now evidence.
They "secure" this behind password which you entered to trigger the SMS push in the first place.
Offering an "out" to a more secure flow means your secure flow may as well not exist.
Additionally, phishing a pushed OTP is not really much harder since you can trigger the push and then just have the user finish off the flow for you, provided they don't read the IP or whatever you display them (they won't, they think they're signing in), effectively the same as a TOTP.