A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Microsoft Authenticator requires a secure, non-rooted, fully supported Android environment for work or school (Entra ID) accounts. On devices that are rooted, jailbroken, or missing required Google services, Authenticator can block work/school credentials for security reasons.
From the documented behavior:
- Starting February 2026, jailbreak/root detection is enforced for work/school Entra credentials in Microsoft Authenticator. If the device is detected as rooted, work/school accounts in Authenticator will not function.
- For Android work/school accounts, Authenticator also requires Google Play Services and Google Play Store to be installed and enabled, with push notifications available.
On Huawei devices that do not support Google Play Services, these security and platform checks can fail, which can cause Authenticator to treat the device as non‑compliant and block work/school usage, even if the device is not actually rooted.
There is no supported workaround in the documentation to bypass these checks or force Authenticator to run work/school accounts on a device that:
- Lacks Google Play Services/Google Play Store, or
- Fails the jailbreak/root detection for Entra work/school credentials.
To use a work account with Microsoft Authenticator, the supported options are:
- Use a different Android device that:
- Has Google Play Services and Google Play Store installed and enabled.
- Is not rooted or modified.
- Use an iOS device that is not jailbroken.
- If unable to meet these requirements, contact the organization’s IT admin to:
- Confirm allowed MFA methods for the tenant (for example, SMS, voice call, FIDO2 security key, or other authenticator apps), and
- Configure an alternative MFA method that does not rely on Microsoft Authenticator on the Huawei device.
If Authenticator still reports the device as rooted or non‑compliant even on a supported device, the only documented path is to work with the IT admin or Microsoft Support to review device compliance and MFA configuration.
References: