Friday, July 8, 2022

Buggish: MS Authenticator on Company Secured Phone; Having to sign in 5 times just to use a site.

Company secured phones can be extremely burdensome in that everything requires an authentication. None of the automated notification goes through until it is unlocked. Because of all this, I missed many 2-factor authentication because it turns out to be almost like 5 authentication steps.


If I do not remember to unlock my phone first and I sign into a page that requires authentication, I have to first unlock my phone. This triggers all the notifications which includes all the emails, all the messages, and all the IM/DMs. By the time, I can even get to the button to open authentication, the login has already timed out. So I sign-in again...

By the time, I sign in again... my phone has locked. So I have to unlock again. Then open the authenticator again, agree, put in the unlock code again. Then watch my sign-in hasn't logged in. Check my phone again, and notice another authentication and repeat. Then I watch my sign-in expire and say the sign in failed because it too short for two authentications. Two because the first one was for the first time that I logged in.

So I sign in for a third time. This time I unlock my phone first. Open, unlock code, agree... and finally in. Sometimes it even fails to log in for some reason and I have attempt a fourth time. And then even sometimes this just keeps failing, then I try on another browser. If that fails, I reboot and do it all yet again.


And our lovely company also likes to use the admin account practice. We also have two domains. So the first step was just to switch domain. So now, I have sign in again to get my admin password. This time with an additional step to put in a code, then put in my unlock code. Copy the admin password.

Go to the site I wanted to go to, sign in with admin account. Then put in the admin password again. Finally, usually I get to where I needed to be.


Why do I need to log in so many times? By the second or third or fourth or tenth time, does the system think that the hacker took over my phone or device or my life? The most likely scenario is that I got so frustrated that I threw my phone out the window at which point I guess then all this security does make sense.

No comments:

Post a Comment