Azokle Auth vs Microsoft Authenticator
Microsoft Authenticator requires a Microsoft account for backup, bundles enterprise telemetry, and integrates deeply with the Microsoft identity ecosystem. Azokle Auth requires nothing but your device.
Feature-By-Feature Matrix
The Empirical Privacy Proof
Verified evidence derived from RFC standards, source audits, and official privacy policies.
Microsoft Collects Extensive Diagnostic Data
Microsoft Authenticator's privacy policy states it collects "diagnostic data" including app usage events, crash reports, and device identifiers sent to Microsoft servers.
Azokle Auth sends zero network requests during operation. The only permissions required are camera (QR scan) and biometric authentication. No diagnostic SDKs, no crash reporters.
Backup Requires Microsoft Account
Microsoft Authenticator's backup feature requires signing in with a personal Microsoft account, uploading your 2FA secrets to Microsoft's cloud infrastructure.
Azokle Auth intentionally has no cloud backup. Your TOTP seeds are derived from secrets that never leave Android Keystore / iOS Secure Enclave. Back up by exporting encrypted QR codes locally.
Excessive Permission Requests
Microsoft Authenticator requests permissions including Contacts, Phone State, and in some versions Location — none of which are necessary for TOTP generation.
Azokle Auth's AndroidManifest.xml declares only: CAMERA (QR import), USE_BIOMETRIC, and USE_FINGERPRINT. No access to contacts, calls, location, or network beyond initial setup.
Closed Source — No Independent Audit
Neither Microsoft Authenticator's TOTP implementation nor its backup encryption has been publicly audited. Users must trust Microsoft's implementation without verification.
Azokle Auth's TOTP and HOTP implementations are verified against IETF test vectors published in RFC 6238 and RFC 4226 Appendix B. All test results are published in our open repository.
Microsoft Authenticator is enterprise-capable but privacy-compromised. It requires a Microsoft account for backup, collects diagnostic telemetry, and requests permissions far beyond what TOTP generation needs. Azokle Auth is purpose-built for privacy: zero telemetry, zero cloud dependency, minimal permissions.
“Enterprise-grade 2FA shouldn't mean enterprise-grade surveillance.”