213
Can I refuse MS Authenticator?
(lemmy.ml)
A loosely moderated place to ask open-ended questions
If your post meets the following criteria, it's welcome here!
Looking for support?
Looking for a community?
~Icon~ ~by~ ~@Double_A@discuss.tchncs.de~
Sure, and I suspect they company will have another option for folks who either can't or won't put the application on their personal device. It's probably also going to be far less convenient for the user. Demanding that the company implement the user's preferred option is where the problem arises.
It's a matter of scale. In a company of any size, you are going to find someone who objects to almost anything. This user doesn't like Microsoft. Ok, let's implement Google. Oh wait, the user over there doesn't like Google. This will go on and on until the IT department is supporting lots of different applications and each one will have a non-zero cost in time and effort. And each of those "small things" has a way of adding up to a big headache for IT. We live in a world of finite resources, and IT departments are usually dealing with even more limited resources. At some point they have to be able to cut their losses and say, "here are the officially supported solutions, pick one". While this creates issues for individuals throughout the organization, it's usually small issues, spread out over lots of people versus lots of small issues concentrated in one group.
If you're in IT, you've likely seen (and probably supported) this sort of standardization in action. I can't count the number of places where every system is some flavor of Dell or HP. And the larger organizations usually have a couple of standard configurations around expected use case. You're an office worker, here's a basic laptop with 16Gb of RAM, and mid level CPU and fuck all for a GPU. Developer? Right, here's the top end CPU, as much RAM as we can stuff in the box and maybe a discreet GPU. AI/ML work? here's the login for AWS. Edge cases will get dealt with in a one-off fashion, there's always going to be the random Mac running around the network, but support will always be sketchy for those. It's all down to standardizing on a few, well known solutions to make support and troubleshooting easier. Sure, there are small shops out there willing to live with beige box deployments. Again, that does not scale.
Hey, if that's your thing, great. But, there is a reason BYOD took off. And a lot of that was on users pushing for it. Having been on the implementation side, it certainly wasn't IT or security departments pushing for this. BYOD is still a goddamn nightmare from an insider threat perspective. And it causes no end of headaches for Help Desks trying to support FSM knows what ancient piece of crap someone dredges up from the depths of history. Yes, it's a bit of cop out to give the user a crappy solution, because they push back against the easy one. But, it's also a matter of trying to keep things working in a standardized fashion. A standard configuration phone, with the required pre-installed, gives the user the option they want and also keeps IT from having do deal with yet more non-standard systems. It's a win for everyone, even if it's not the win the user wanted.
I do understand how bad Microsoft can be. I was an early adopter of Windows Me. And also have memories of Microsoft whining about de-coupling IE from the OS. And I don't want MS to win out as the authentication app for everyone. That said, I still believe that the Microsoft Authenticator app on a personal device is the wrong hill to die on. There is a lot of non-Microsoft software out there and there are plenty of options out there. But, Microsoft software using the Microsoft app isn't surprising or insidious.