Why did Personal Vault authentication change?

Anonymous
2022-10-10T17:31:28+00:00

It used to be that when I accessed my Personal Vault, it would ask me to authenticate with Microsoft Authenticator. That suddenly disappeared, and now it gives me the options of authenticating with a fingerprint or my PIN. I don't want my PIN to work to get to my Personal Vault. Other people use my PIN to access my machine. I don't want to use the same authentication to get to my personal vault. I want that to go to Microsoft Authenticator so that it is different.

Why did it change, and how can I change it back?

Microsoft 365 and Office | OneDrive | For home | Windows

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

44 answers

Sort by: Newest
  1. Anonymous
    2023-02-27T19:30:20+00:00

    What other consequences are there of unlinking your MS Account from Windows? I'm not clever enough to understand fully what that means. Does the rest of OneDrive work still?

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2023-02-27T03:11:18+00:00

    I have considered this, unfortunately it results in either a loss of functionality ir of security.

    With the way it had been working before recent changes broke it delivered two operational scenarios:

    1. Normal operations where I sign into my device via PIN. The device is trusted and my normal files, links, etc sync automatically among my 4 devices. Works great since I routinely move to multiple devices each day.
    2. Personal Vault access where I keep my most sensitive personal documents. To open used to always require entering a separate code from the MS Authenticator app. This was true TFA requiring access and use of an entirely separate device and app. Some what inconvenient but worth it for signicantly greater security.

    Again, it appears someone ‘fixed’ something that wasn’t broken and really didn’t understand the security implications.

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2023-02-27T02:54:57+00:00

    TFA that requires a real-time secondary authentication is inherently safer than any method that relies solely on a single factor or physical possession of a key or fob.

    Personal Vault used to have a required TFA step.

    The potential for someone to physically possess one of my computer devices and or my PIN is certainly within the realm of possibility.

    The potential for some to possess the above AND to have my smart phone + the authentication to my phone is a magnitude less likely.

    I started with a trial subscription, determined that it met my requirements and purchased an annual family subscription.

    The TFA requirement changes the fundamental decision for my purchase.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  4. Craig Long 18,635 Reputation points
    2023-02-26T19:29:29+00:00

    Why use 2FA when you can choose one of these? I would choose the physical security key for everything and am thinking about getting one. However, I may need to fall back on one of the other methods also.

    Image

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2023-02-26T16:53:21+00:00

    It sticks. I made several reboots of my laptop and behavior of OneDrive app is the same. It requires 2FA. Unlocking my laptop is still possible with fingerprint/PIN. So, no major disadvantage at this moment.

    Was this answer helpful?

    0 comments No comments