Hacker News new | ask | show | jobs
by kevin_thibedeau 1511 days ago
Yes they do when your M365 using employer insists that you have to use the authenticator app on your personal phone and won't provide an alternative option.
1 comments

At no point during setup does Microsoft Authenticator app collect your mobile number. That is in fact the whole point of the app: SMS is insecure for 2FA so collecting a mobile number makes no sense.

Most of our people including myself choose to enroll a personal phone rather than carry two devices, and somehow none of these hundreds of people ever provided their mobile numbers to Microsoft. I think you are mis-remembering the setup experience, or your employer chose to enable some non-default options that uses SMS as a backup option to the app.

Prior to Android 11 no permission was required to retrieve a phone number via the API.
Do you have evidence from the apk that phone numbers were being retrieved?