Hacker News new | ask | show | jobs
by tatersolid 1511 days ago
No they don’t. I run an M365/Azure shop and not a single user out of hundreds has given their mobile number to Microsoft.

My personal consumer MSFT/Xbox account also has no mobile number attached.

1 comments

Yes they do when your M365 using employer insists that you have to use the authenticator app on your personal phone and won't provide an alternative option.
At no point during setup does Microsoft Authenticator app collect your mobile number. That is in fact the whole point of the app: SMS is insecure for 2FA so collecting a mobile number makes no sense.

Most of our people including myself choose to enroll a personal phone rather than carry two devices, and somehow none of these hundreds of people ever provided their mobile numbers to Microsoft. I think you are mis-remembering the setup experience, or your employer chose to enable some non-default options that uses SMS as a backup option to the app.

Prior to Android 11 no permission was required to retrieve a phone number via the API.
Do you have evidence from the apk that phone numbers were being retrieved?