Use Microsoft Authenticator for easy, secure sign-ins for all your online accounts using multi-factor authentication or passwordless. You also have additional account management options for your Microsoft personal, work or school accounts.
Quick Verdict
Best for: General use with standard privacy expectations
What It Means For You
Usage data and device activity may be shared with the app developer and any integrated services. Review the category summary below for details.
Quick Verdict
Best for: General use with standard privacy expectations
What It Means For You
Usage data and device activity may be shared with the app developer and any integrated services. Review the category summary below for details.
Method and Limitations
Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.
Data Security
2 totalNetwork Security
1 totalCode Security
4 totalPrivacy
4 totalVersion diff is on the Developer plan. See developer plans.
Context Tags
Package
com.azure.authenticator
Version
6.2603.1485
Analysis Date
Apr 17, 2026
Classes Analyzed
31,000
Feedback helps us improve our analysis
Essential for Microsoft accounts, but includes an older two-factor code storage method alongside newer encrypted storage, and sends location and organizational data to Microsoft through telemetry that cannot be fully disabled. Privacy-conscious users should review Microsoft's data collection practices before relying on this app for non-Microsoft accounts.
Data Security - 1 finding (1 medium)
Network Security - 1 finding (1 low)
Code Safety - 3 findings (2 low, 1 info)
Privacy - 4 findings (2 medium, 1 low, 1 info)
The following third parties may receive your data:
Security: 89/100
Privacy: 30/100
The app's privacy practices could be strengthened by:
Opt-Out Coverage for Required Telemetry
Currently, certain telemetry events including organizational tenant ID and location precision data are transmitted regardless of the user's optional telemetry preference. Extending user opt-out rights to cover these required events would better align with data minimization principles.
User Review Before Automatic Diagnostic Uploads
Crash reports that include account identifiers are automatically submitted when the app crashes. Providing users with a review screen before transmission would give them meaningful control over what account-linked data is shared with Microsoft.
Explicit Disclosure of Location Data in Telemetry
Location precision metrics are transmitted during authentication events even when location access was not required for that specific sign-in. Clear in-app disclosure of when and why location data is included in telemetry would improve transparency.
Remove Profiling Flag from Production Builds
The app's production release includes a configuration flag that allows development tools to attach a profiler to the running app over a connected cable. This flag is intended for pre-release testing and should be removed from production releases.
Migrate Device Registration to Modern Encryption
The Workplace Join device registration process uses an older encryption standard for protecting private keys in device certificates. Migrating to a current algorithm would bring this component in line with current industry standards.
Complete Migration Away from Legacy Two-Factor Code Storage
The database retains a legacy column that stores two-factor authentication codes without the newer encryption protection applied to the primary column. Completing the migration by zeroing the legacy column after encryption would eliminate this residual exposure.
App Type: Multi-factor authentication and identity management, high sensitivity
Classes Analyzed: 31,000
Third-Party Services: 18
Context Tags: sensitive_data, location, camera, enterprise
This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. We perform static code analysis on Android applications to help users make informed decisions about app security and privacy.
Developer: Microsoft Corporation
Version: 6.2603.1485
Analysis Date: 2026-04-17
Package: com.azure.authenticator
Developer not yet contacted