My daughter's school took over my personal Microsoft account(jeffgeerling.com) |
My daughter's school took over my personal Microsoft account(jeffgeerling.com) |
Is it possible to convert that to a local login?
Take comfort that some things never change!
It's a pain in the tail to resolve, but it can at least be resolved without calling the school.
The thing about the Trello account is that I used a non-school email account for that. I never at any point gave them information about my school account. I opened the account on the day Trello was announced, when they didn't even have paid plans. I'm guessing they were able to link me somehow, and they used that information to give my account away.
Clearly Atlassian is not a company that should ever be trusted with important data. In my case, if I had any information about grades in my account, it would have been a violation of FERPA. You can't casually hand out that information to random strangers.
HOWEVER, the article glosses over the real story: a child obtained complete, unsupervised access to the author's computer, and wouldn't you know it, they broke something.
I suspect there would be far less interest if the headline read "my kid ordered $20k worth of Robux and I can't get a refund".
Given the advent of and ease of use of password managers, I'd rather just have another set of credentials than risk the inconvenience.
It's strange to me to take the discussion like this to public forums before talking to the people involved. It could be his daughter "gave" it to the school as an act of generosity for example.
In short - you are missing a lot.
But the fact that it's even possible to reach a failure state like this is still worth public discussion. You're probably right, odds are his daughter hit "okay" on some screen... but it shouldn't even be possible to irrevocably hand over the keys to a private account.
That shouldn't possible in the first place.
Too bad that they didn't let you make a copy of what you had - mistakenly - stored on that account though.
PS - Suggest you don't make the mistake of replacing that with a personal Google account.
In this case, is there another company with a similarly old and complex auth system that does exemplary work?
Some kind of Stockholm syndrom.
Here in the Netherlands they somehow have convinced local governments (like cities & provinces) that working with them is still GDPR compliant, even thought they should only work with EU based companies to store data. But other companies like DigitalOcean, AWS and Google cloud (especially Google is evil) are not GDPR compliant
As a dev learning web development when IE was still a thing I still have horrible experiences with them
100% pure regression with account management.
About 10 years ago I created an Azure account with my normal email and my US address. I did some stuff but never had a reason to use Azure in a situation where I’d pay for resources. Some years later I wanted to check out Azure for a small project. I go to log in and it tells me I need to add billing or something. I enter my credit card info and get to the address section. My zip code won’t validate. That’s odd. It’s saying it wants numbers and letters. Wait why does it think I’m in Canada? I’m in California. CA? Hmm. Anyway should be easy let me fix the Country. Oh it’s greyed out. YOU CAN’T CHANGE THE COUNTRY?!
Surely this must be a bug. File a support request. Nope can’t change country. Escalate and explain that I can’t add a credit card because I am not a CA resident and don’t have a Canadian payment method. They tell me they can’t change for tax reasons. But they never took my money because I can’t pay them… I go on to tell them I never even selected Canada there must be some UI bug when they first rolled out the new account format. They said theres a known issue where this can happen. I ask them to fix. They can’t because taxes. They tell me I have to create a new email if I want to use Azure. I wont do that because I have virtue.
I try two more times over the course of 6 or so years. Both times I’m escalated to someone who thinks they can fix the problem for me. I think at one point there was a technical work order put in to delete my Azure account so I could try again. But somehow it always gets thwarted.
So what happened? I’ve been able to piece together that Azure transitioned to a new account model between when I first created my account and when I tried again the first time. The old model was independent of your MS account. The new one not so much. Somehow Azure migrated my legacy account with a US address and morphed it into an account with a Canadian country set. This Canadian account is intimately linked to my normal MS live account which has a US address and payment info nonetheless. An early version of the Azure account migration UI locked in your country before verifying your payment/address. For “tax reasons” you cant change but it’s totally fine that my US live account has a Canadian Azure account and that, if I was able to do things as MS wants, I’d be paying for MS apps and services with a US card and Azure resources with a Canadian one. Because that’s better for taxes?!
So to this day I can’t use Azure because I’m not willing to change my live account login email address, my main email address, to something else just to work around MS’s bullshit. Because yes, now it’s all the same and your azure account is your live account.
That’s a known issue and we have a simple workaround: just kindly make a new email address…
The school did not "take over" his MS account. At some point (likely amidst a mountain of other onboarding tasks for his daughter's enrollment) he would have received an invitation to join the school's Azure AD tenant as a guest/external user. In this case, he chose to join using his Microsoft account, rather than create a new email-based guest account.
"Leaving" the school's org only breaks one side of the federation, and the guest account and it's association to the school's Azure tenant still remains.
To resolve, he'll need contact the school and have them delete the account. Meanwhile, it probably would have been better to create the app beneath an Azure AD tenant belonging to the non-profit org in the first place.
Anything that gains such traction gets fixed eventually, but I want them to fix the root cause, not just this instance of it.
1. My son's school MS account took over his private account, only because he linked the two accounts.
2. Suddenly my son's Windows said it was un-authorized.
3. We called Microsoft, they could not fix it.
4. We called the manufacturer of the machine (they shipped Windows as OEM). They could not fix it.
5. Called MS again. They gave us a new activation code. Did not fix it.
6. Called MS again, this time they said to reinstall Windows (This is not a joke).
7. Upon re-installing, Windows would not activate. No error message, no nothing it would just hang in the activation loop.
8. Called MS. They had no clue. Claimed H/W issues.
9. Called manufacturer again. Also claimed H/W issues. I said that I can access the internet from the machine while it was hanging in activation, so network was not the problem.
10. Manufacturer sent someone out (I had bought warranty). He switched the SSD with a new version of Windows... The did exactly what I did. Same problem, would not activate.
11. Some back and forth with MS and the manufacturer involving many reboot and (I kid you not) turning off all wireless routers... MS still would not activate. Manufacturer (and MS) did not believe me. So they sent someone again. Did the same thing, again. Did not work.
12. Manufacturer said I needed to send in the machine. So I did. I included a note about what the problem and to please not just re-install Windows, because the activation was the problem.
13. Got the machine back... They had just re-installed Windows. Would not activate.
14. Started to get upset. After some pressing manufacturer agreed to send a new machine.
15. First they sent someone out again. Did the same thing again. Forced me, again, to turn all wireless routers off, so that (he claimed) Windows would activate without network. Again... Did not work. Activation just hung.
16. Eight weeks into this we ended up getting a new machine (yes, not kidding) from the manufacturer and now the same version of Windows (from the same memory stick) on the same hardware, same drivers, all the same, would happily register.
I cannot even begin to express how annoying and useless this was. And MS and manufacturer were helpless and useless.
Personally I have stopped use Windows over 2 decades ago - only using Linux, but my son wanted a gaming machine, and so I relented. :)
It might not work for some of the multiplayer games that youngins play although it might work.
Microsoft bought Github in 2018. We'll see what happens in 2025...
He explicitly claims he didn’t, by the way.
And some people speculate my daughter may have logged into an account on my computer—there is no possible way, and at home she only uses one of two other devices (and at her school they don't have students log in off premises anyways), and my two computers are locked at all times when I'm not around.
In addition, assuming she were able to get access to one of my computers, the password manager is behind face/Touch ID and locks automatically after each use.
I spent a couple hours digging through all the emails we got from her school too, for the month preceding her entry into the school, and I saw nothing about any online logins, not even a link to any kind of portals or anything like that... just consent forms, welcome messages, and the like.
I've been racking my brain for a logical explanation as to why my personal email (and the password associated with my personal Microsoft account—which has been used to login to Azure in 2020, years before this mess) has been associated with the school's tenant. I can't find any.
Speculation.
And even if he received such a mail, were the consequences made obvious to the user?
People learn how to navigate a shit system and them become complacent with it, blaming the less experienced with their "errors", when the system itself is wrong for being shitty.
This is just a convoluted why of me saying: don't blame the user
Nonetheless, I would have expected MS to ensure that the process includes clearer guidance for the account owner, and for deliberate decisions to be made by the school to enable this type of action.
They did a very good job of providing clear advice to BYOD users during the MDM onboarding process in InTune, and it’s confusing that this didn’t occur in this case.
No matter how inexperienced they are, it shouldn’t be possible to put an external Microsoft account into this weird state without the account holder’s permission. And the “leave organisation” button shouldn’t leave the account in some weird unrecoverable state.
This all reeks of sloppy product design on Microsoft’s part. Is my Microsoft account one bad domain administrator away from being taken from me? That’s unacceptable.
The school's IT team should never have had the means to do that.
It's a long time pattern of behavior from Microsoft about their utter lack of any care or thought for how to manage their MS Accounts system.
Giving such permissions to a 3rd party could be just a gross incompetence instead of malice. Yet, it should never happen.
And then Jeff is confused about the state of his account. Keep in mind that he's using a developer tool (the Azure portal) and account federation is not a beginner-level feature of Azure AD. There are sharp edges. He just jumped to a lot of conclusions and wow the Fud level on this comments thread is off the charts.
I know this because I set up an OAuth2 based web portal for my friends to access my Minecraft server using Azure AD B2C and by god the hardest part was figuring out how to explain the login experience to users, and disable the secondary 2FA requirements for MSA/Gmail users (because I know my friends are smart enough to use 2FA)
That is a personal account shouldn't even be possibly converted into an AzureAD one: if you want it's another account, with another email and another password. This possibility of mistake should never happen.
The trial ended, Microsoft start charging my credit card, and it was literally impossible to stop it without access to the account that was managed by the now defunct company. While it was pretty hard to talk to an actual person, I did twice, and after months of back and forth via email, I was advised to just do a charge back with my credit card company. Microsoft (probably automatically) disputed the chargeback, and I spent many more weeks disputing the dispute, having to prove to my credit card there was no way to cancel and Microsoft actually told me to do a chargeback. I'm sure I'm somehow banned from Microsoft accounts using that credit card, although I've never tried.
I told him that good luck coming all the way from India to wrestle my laptop from my hands. Don’t know if this will end with me looking for a new job, but what I know is that I won’t be installing whatever rap they are pushing. I am an adult and know how to admin my own computer
I'm usually pretty positive about Msft but their identity stuff is a mess.
[1] except that I have two OneDrives that appear to form a Venn diagram with a partial intersection that i can never quite figure out....
I’d be curious about a follow up if the author ever figures out how the account takeover happened. I wonder if logging into the account on a school device resulted in automatic enrollment or something.
Our team has a Google sheet with some scripting that uses the data in the sheet to generate data to another system. This needs to be run using the company Google account.
Now someone opens the sheet, runs the script and it just doesn't work.
Why? Google just randomly decides to pick one of these:
- The personal Google account the user has logged in to - The account used by Chrome - The company account
We haven't found a pattern to this yet. It works better for some people and worse for some depending on the time of the day, position of the planets and maybe a third unknown factor.
It took a lot of back and forth with the schools admin to figure out what happened. I was able to get my account released, but I wasn’t brave enough to try what Jeff did.
Like Jeff, this did not leave me impressed with MS Azure at all. How could joining (or being added) to a mailing list imply you are now part of an organization? How does one go from LDAP to that hosted AD mess?
It brings plenty of other headaches though.
What has happened here is that you have essentially two accounts: One is your consumer MSA, and the other is an account in the school's Azure AD instance that uses federated sign-in with an external account (your MSA). Except, the real mess comes from the fact that there's one login page for both, and sites such as the Azure portal that support both identities and can't really tell which one you expect to assume. Plus, the Azure portal lets you switch between Directories at any time.
You can:
* Sign out completely (login.microsoftonline.com/logout.srf) and sign back in. The reason the sign-in page asks for your sign-in email first is because then it uses that to decide which directory (MSA or someone's AAD) to sign you into
* Change directories - (in fact I'd recommend creating your own Directory instead of using the one that was automatically created for you from your MSA name)
* Create a consumer MSA based on a Gmail account
* Invite that MSA into an AzureAD directory
* Try to sign in as that user to that directory.
Good luck!
I have 2 Microsoft accounts on the same email address, one is a personal account I created ~ 10 years ago and one that appeared out of the blue a few years ago. The second one seems to be created by my employer, when I try to login it is rerouting me to the job 2FA. The weirdest thing was when I tried to schedule an exam with Microsoft and it appears as free on the work account, for some reason, but not free on my personal account.
I also had OneDrive set up on my personal desktop. After years of working well, one day I got an error and I had a look: it merged my personal OneDrive with the work one, so my Witcher 3 saved games were on my company's storage. I guess this happened because I tried to add my work account in Outlook to read email on that computer too. Since then, I am doing all the work related tasks in a Virtual Machine with a local Windows account and no email, no Teams, no OneDrive, etc.
Worked on a project for a big bank. My work email was given access to their Active Directory or whatever for certain sharepoint folder access.
My work machine is signed into my /personal/ microsoft account for login, and then also signed into my work-personal account (i.e. MS account with my work email, but a self created personal one - we're not an MS company).
At some point I was kicked off my Xbox, had to do a password reset dance to get access again, all because Big Bank's password expiry policy somehow leaked into my personal MS account thanks to being signed into both accounts on the same pc.
And now, my company got an Active Directory for us, purely to make interfacing with other MS-powered clients easier. Imagine the nightmare of my work account, originally created by myself, and the conflicts with my new "work or school" AD account. It's such a mess.
It appears that someone was able to link an MS account to my email with no verification, then rename the account, again with no verification.
Best case is that it's someone who used my email as a recovery email for their MS account and changed it. But with the mess of MS accounts, I'm always nervous they've got some residual control of my real account which is also linked to that email.
Unfortunately I've never been able to get confirmation from MS that things are OK. There are plenty of questions about this particular renaming issue on the web, but no answers.
And also this is why I don’t use Ubuntu anymore.
I know this because I have one of each running in my home with no associated cloud accounts whatsoever.
They do nag you a bit (not aggressively like Microsoft, who is like "are you sure you want a terrible experience using this computer?"), but it is entirely possible to be productive outside of the iOS ecosystem, which does require an account to load apps.
Microsoft Office is a big deal. It's where the worker lives.
This is because Google didn't spend the money to make workplace software better than Office, only clunky web apps; while Microsoft spent the money to make web apps (nearly) as good as the workplace software everyone uses.
Google chose not to displace 80% of features of the incumbent, while the incumbent added the 20% Google had thought was enough.
So 85% of business workplaces and workplace users are O365/M365 workplaces and users.
Btw, if you make SaaS and don't support "Login with Microsoft..." or their (very easy to integrate) SAML SSO, you're leaving 85% of your TAM on the bench.
See https://www.xsplit.com/user/auth as an example of a sign-in that enables every workplace and identity.
At the end of the day its something I'm more disappointed than upset about. Its scammy, gross, and reflective of a company playing catchup by force.
It’s funny because Azure seems like it’s just a hacky scaled up version of what MSPs we’re doing with hosted exchange 15 years ago.
Try and see it from their perspective.
This entirely depends on whether the company supplied or paid for the device. Given they're trying to install MDM after the fact, it sounds more likely to me that they didn't. In which case if they want that level of control they should buy their own company equipment.
Just no. Our IT department is 100% Windows focused. I can't get help to anything that isn't "a Windows problem". I can't get ports open in the network, I can't get simple things like mosh to work, because again it is not "a Windows problem", so I am not going to let them screw my perfectly fine machine with some Windows bloat ware there is a reason why no one is dev is running Windows.
This actually is a hill I am willing to die on. If I can't use my machine how I see best then I can start accepting any of the interview offers my spam folder is full of.
Worker cost 50 money. How company get 50 money? Worker not work so much, maybe? How to quantify? What if spy? Company tell IT monkey to give developer monkey spy. Our computer, company can do a little spy. Company catch smoke break. Company catch walk break. Company give worker "performance improvement plan." Company fire worker. Company now have 100 money. Company smart. Company efficient. Company legally protected from retaliation. Company give executive monkey 30 money as reward for small overhead. Company offer manager monkey 7 money. Company offer IT monkey 3 money. Company brag about in annual report.
Is it ecological? No. But the compliance beast must be fed. So fine.
> malice is a condition of the mind which shows a heart regardless of social duty and fatally bent on mischief, the existence of which is inferred from acts committed or words spoken.
Negligence and recklessness are often considered acts of malice, especially when stemming from wilful blindness.
The mischief here is the problem with the account, we (those commenting on this page) have no confidence in Microsoft to improve it (they are fatally bent), as they clearly don't consider it a social duty and are surely wilfully blind to it. Does anyone here think they want to know, let alone care?
One wonders why one would pretend not to know this.
This is exactly the kind of waste we should get rid of, but sadly this is exactly what we get by offshoring IT into India where people just do exactly what some consultant tells them to do without any critical thought if it is appropriate or not.
Trying to be actively signed out is also a mess. You can use the teams app to join teams meetings others have setup and invited you too without teams access yourself. Though of course if you have an MS account teams can see it ends up trying to use it and then saying you don't get teams access via that account and trying to sign out and join the meeting with an account associated with it often just doesn't work. A colleague actually ended up requesting he got an o365 account with teams associated with his corp email because of this issue as he had occasional meetings with external people over teams. We have a corp o365 setup for our ops/admin team that engineering normally doesn't touch but because he had a teams invite sent to his corp email he got dragged into it.
If he would have graduated or otherwise no longer have access to his school account, he would never have been able to recover the drive. Of course he has his important files in cloud storage anyway but it’s very annoying nonetheless
>>Of course he has his important files in cloud storage anyway
So MS's defective key system is pushing people to keep their files in the MS cloud? When a defect in one product pushes users towards are more profitable/addictive product, that isn't a defect. It sound like the plan to keep users hooked into the MS ecosystem is progressing nicely. Once upon a time it was Apple getting its hooks into users while at school. Now it is MS.
Does one still need an MS account to play minecraft?
they tried to simplify it by tying everything to yubi keys, but just this week some things stopped going to the yubikey and wanted me to auth on my phone like we used to instead.
ugh
That doesn't sound reassuring if the cloud storage is, itself, Microsoft connected ... or even using auth/login mechanisms that connect to the Microsoft account.
And then you get the people asking naively "why are you getting so mad at them"...
I just want to point out that this entire described scenario, by a company with decades and decades of security products being shoehorned into "just good enough" cloud infrastructure....
Sure the security folks will say hardened infrastructure with fine grained least privilege is doable ... if you're at greenfield ... maybe. But the issue with lots of IT orgs is that they are MESSY, and fine grained least privilege is fragile. Messy + fragile = not good things.
I agree with least privilege as an aspiration, but security is a top-down authoritarian entity in organizations, and fundamentally they don't care if their policies disrupt your daily work process. IMO this is because most security orgs don't provide solutions.
Specifically, by solution I do not mean "picked an enterprise security product bam we have a solution", I mean you have a security architecture and then have the people with bandwidth to help boots on ground devs get the job done quickly so security isn't a blocker).
If you use firefox, you can use each other the container types to host different login accounts, it makes it easier than switching between private windows and doesn't require you to enable extensions on your private tabs
It is indeed a giant mess.
If you go to live.com and click on the hamburger icon at the top, then under 'Apps' click on the "To-Do" app, you will be asked to enter the password for your work account, even though you are on live.com, not on office.com, and you are currently logged in with your personal account.
The only way to get past this is to click "use another account" then log in again with your personal account (even though you are already logged in!!).
This bug has been present for months now.
They’re actively enabling phishing because they choose to rollback standards support.
https://www.brightball.com/articles/how-microsoft-became-phi...
The many standards around identity management makes the web more complex. Most of us have many identities and we end up with a multidimensional web of tokens and cookies.
I think at some point something will have to give. This seems like a space where some more provider consolidation or collaboration would help.
Security is so important to get right, yet too easy to get wrong.
Doing the same thing with MS accounts has been an utter nightmare by comparison.
For that reason I never use MS online apps on my private devices and whenever I need to sign in online, I always use the private mode or a dedicated Firefox container.
It looks like generations of implementations (and likely generations of product management and development teams) layering on top of each other, "replacing" the "old" systems only to do the half of it, and integrating with acquired products.
Seen from outside, it just doesn't look like there exists a single team that understands the authentication and permission system end-to-end.
In my case, my personal and professional Microsoft addresses are the same (same email, different accounts) which means that in many cases I end up in impossible situations when the login screen doesn’t correctly guess if I want to sign in personal or with my “work” account. I also do client work for organisations where I need to sign into their O365 and honestly the only way to manage all that is to keep a dedicated browser “per account”.
Teams is a different story, I avoid account switching because exactly like you describe, sometimes I need to uninstall it in order to sign out.
It's the only way I can keep my personal, work, and alma mater email separate and not falling into login loops.
Basically when we login we need to use the "personal account" but sometimes it will not ask what account to use and automatically choose the wrong one, and once it gets stuck in this state i didn't find a way to fix it.
Arguably, if you're one of the 85% of SMBs in O365/M365 instead of Google Workspaces, or if your "Login with..." personal account is Microsoft instead of Google or Apple, you should be using Edge.
I agree. It is surprising that we don't see similar issues more often. It is *so* confusing to both users and the developers, to the point where it's too easy to make some naive mistakes. And it is one of most critical parts of the systems!
- Use different browser profile for each account
- 2nd and subsequent account - use Teams in the browser - in the respective browser profile (teams.office.com).
Teams in the browser is not substantially different than the desktop app.
Apple is not really any better. God help you if you accidentally lock your Apple ID, you will be subject to a month-long wait before it can be fixed. Why that long? No idea. Nobody at Apple has any idea why it couldn't just be 2 days, and they will frankly admit to you that it makes no sense, then spout some meaningless 'because of GDPR regulations' nonsense that has absolutely nothing to do with GDPR regulation.
Even worse, Microsoft is now trying to force online accounts onto Windows machines.
Google already does it with Android. Which means for some reason if you lose access to your email, you are locked out of not only your online accounts but your local devices also.
We really need to separate authentication from services and devices. With strong safe guards around that account and an actually support system.
How was this missed when designing the security and authentication systems?? This is basic foundational stuff!
I’ve been in similar scenarios — the switch directory or switch organisation technique usually worked for me - but wasn’t enough for this person.
They never really give you enough information to tell what’s going on… maybe it’s a security risk to have consumers who are anything other than bewildered Kafkerian characters struggling against a faceless bureaucracy? I suppose we should not question their wisdom and be thankful that we can log in at all.
Atlassian manage to make it even more confusing than Microsoft. So there’s that.
I'm skeptical of the suggestion that the school admins were able to do this with no input, but I'm absolutely willing to entertain the idea that:
a) AD login is a complete mess, and
b) the UI is utterly misleading and near-unusable.
IMO, The main issue in here is BigTech obsession with a single login. One single credentials give you access to everything, from entertainment to professional services.
People do share their credentials with family, specially if involves subscription and payment. BigTech try so hard to push for not sharing, but they fail to understand (or don’t care) that most people, specially non American, don’t have the budget to subscribe multiple time. Family accounts are non existent, lacking management options, and also more expensive.
I don’t mean to solely focus on Microsoft, but they are the dominant example in their domain and the biggest example in tech.
As a society it should have never been allowed to even be possible that things like the government, including public schools, become so captured by Microsoft’s disastrous ecosystem. People give Apple some justified flak for lock-in issues, but at least there it feels more like Apple trying to keep the horrors of especially Microsoft and Google at bay … formal dress required for entry.
My personal account was tied to that tenant, and whenever I tried to register an app - it was access denied. They even give you an option in the app registration interface in Azure: whether you want it to be in the company tenant or linked to your personal account. Regardless of what I tried, access denied. After a few weeks of this, I attempted to “Leave” the proof of concept tenant.
Yes, I clicked the scary leave button that tells you your data will be deleted. Access denied.
One of the options Microsoft suggests is to get in contact with the global admins to help out. Considering that tenant was abandoned 8 years ago, it was going to be difficult to get in contact with the global admins. I even contacted my former employer and requested they remove me. Their response? “We abandoned that tenant years ago, no one can access it”.
I created a support case with Microsoft for their Azure AD service requesting they remove my account from the tenant.
After some back and forth, repeating myself a few times, trying to explain what I save wanted to do in multiple different ways, and a screen share, I still wasn’t able to leave the organization. The case was escalated, and eventually I got on a call with the support rep and a manager.
We went through the “leave the organization” process together, and miraculously, it allowed me to leave. This was several months ago, by the way, and no data loss with my personal account that I can tell (so far), although I can’t guarantee when you click that scary button, your data will be safe.
I’m not sure what technical witchcraft took place for this to happen, because it was the exact same set of steps I had tried 25 times before. My only point in this story is to say it would probably be worth a shot creating a support case with their Azure team, and being a squeaky wheel, in the behemoth cog that is Microsoft, that gets the grease.
First customer service will be automated or even non existant, and very poor. Secondly the product will have been 'tweaked' so many times for new markets and product extensions that it will be very fragile when you do something at the edges of its functionality (not what the other hundreds of millions are doing).
It shouldn't really be this way - it tells a lot about software engineering that a product run by a few enthused people alone can often (but by no means must) have better support and service than a product with huge resources.
Also, a software engineering product run by a large organization is going to have tons more functionality under its much bigger umbrella compared to a small team with a much smaller product. Consider AWS vs Digital Ocean. Both great companies, but AWS's umbrella of offerings is vast compare to Digital Ocean.
No, but something unusual went wrong and getting it fixed will be harder at MS than a smaller company. There probably isn't a single person who understands why without a fair amount of research. Without the publicity, MS would be inclined not to spend the effort to fix.
> Also, a software engineering product run by a large organization is going to have tons more functionality
This was exactly my point - the large product with tons more functionality will likely be more brittle, harder to use, and get support for if something breaks. If you aren't using that functionality, you often won't be well served by the company. I had this experience with EverNote. I'm also a very happy AWS customer, but I think that is because their products are a set of (fairly) independent products, rather than one huge system.
Take but one bad example. If you look carefully, the sign in page for OneDrive is slightly different to the sign in page for other Microsoft services. It has functional differences too, namely, OneDrive's login page doesn't offer you FIDO2 passwordless authentication. Meanwhile, over on Google, everything goes through a unified login screen (accounts.google.com).
They’re better at offering a switch account ui in some places but definitely not most.
So instead of:
https://mail.google.com/mail/u/1/#starred
bookmark:
https://mail.google.com/mail/?authuser=foo@bar.com#starred
The URL will be immediately rewritten as the proper /u/# for that user (which, as you say, depends on login order).
Not sure why it's like this, but I could see it being related to not wanting PII in the URL.
Better then ms teams mess, but then again, it would be hard to make it worst then that.
I so regret converting my Minecraft account. The old Mojang stuff was so much more reliable.
What freaking organisation is always my response; I've never been able to figure it out.
Whenever I see such a serious warning, I will almost always take a long period of consideration before proceeding. Remember that you're dealing with a company which acts like they believe you shouldn't own your computer. If a company with that attitude believes they should warn you about something, it's certainly serious.
Also, Microsoft's UIs are filled with misused terminology. They use create, open, add, (delete, close, remove) etc. interchangeably. For example, in the OWA the process for removing a calendar you don't own is called delete.
Dont forget the og domain, hotmail.com
1drv.ms (OneDrive file sharing)
microsoftonline.com (something to do with Azure)
b2clogin.com (replacement for microsoftonline.com)
Later, I filled out my taxes in Excel and saved them.
It had uploaded them to my school's default OneDrive shared folder. It never asked me if I wanted to use that account as my default, and never told me it had changed accounts. It took me 10 minutes of non-sensical "file is locked" messages before I could delete my private data from my school's drive.
Some apps such as Microsoft Authenticator won't even let me remove the account.
In Chrome you just create a new profile for each identity you have. If you're opening random incognito windows or using different browsers all the time to log in with different identities, you should be creating profiles instead. Everything is separate including bookmarks, sessions, cookies, extensions, etc.
https://addons.mozilla.org/en-GB/firefox/addon/multi-account...
It's just easier for me to manage that way. That being said, my work google account is connected to my personal phone which is probably gonna mess me up at some point.
Yes, even if work doesn't provide a laptop for work purposes and you need to furnish your own. Same goes for phones, etc.
It might be expensive to maintain dedicated hardware to cordon off work from everything else, but it's still cheaper than if you hadn't and the inevitable biological waste impacts the aerodynamic wake generator.
Hoping this raised issue helps cleaning up some of the mess, I find it fascinating how bizantine microsoft have become.
I also have a skype account that became some other other account, but was using the same email as my mojang account that got ported to live accounts. I kinda hope everything is neatly bound in the backend as I login through the live.com portal, but it feels like a miracle that it still works at all.
It was the same kind of fun trying to log to flickr with a old converted yahoo account. Or dealing with amazon after merging multi-coutry accounts.
Amazon used to allow having multiple accounts with the same email, but different passwords. And don’t ask what happens to personal accounts that get accidentally invited to corporate accounts via email adresses formerly used for the personal account.
I made a point to separate mail addresses by country to avoid getting hosed, but I'd imagine the fun trying to access Prime or kindle purchases from an account that has them in multiple national stores.
This is a great thing for small startups, else we would only have a single huge corporate conglomerate doing everything with cutthroat efficiency.
Add to that various attempts at fixing problems, adding features, partially removing unsuccessful features, supporting old systems, framework/library migrations in various states of completeness, different developer's ideas of how to do things, and that rockstar developer who wrote really obscure code and then left to grow pomelos, and you have an incredible mess without even having to bring in company bureaucracy.
WTF kinda power trip are they on when they let domain admins just pwn accounts like that? How did OP end up in this situation? Was his email just on a distribution list and usurped that way? I don't get it. And I find it kinda freaky.
Many Linux distributions have signed bootloader and kernel, to support secure boot, but otherwise I think you could either add your own signing keys for the Secure Boot, or chain either Linux or Haiku from a signed grub bootloader.
In general, be careful what you click agree to (I know, I know)
If you have your daughter login to her school account, and remove your email from her account. Your account will revert to a normal microsoft account.
You will however have very limited access to azure with a personal account, and doing things like registering an app is going to be unlikely unless you have your own tenant, or added to some other tenant.
Just accepting every horrible thing in the world must be so sad.
Some of their designs are downright malicious (like locking the email account until you give them your phone number), more often it's amazingly bad software/UI, and sometimes they'll ruin your weekend by rolling out a Windows update without asking which wipes your partitions or throws bluescreens on boot.
I decided a while ago it's not worth it for me and stopped using as much MS related stuff as possible, and I'm glad I did.
So usually pressing the wrong option while logging with a new one and existing cookies from another one can land on this mess.
Usually the only way out of the mess is somehow via Microsoft support, which I only saw being successful via MSDN sales contacts.
Some years ago, my android tablet could only read my work's office365 mail if I allowed a microsoft app to reconfigure the security. Next thing I know, I can only log in on it with my work AD account. But the WIFI is disabled, I can't enable WIFI without logging in, and WIFI is required for the AD logon process. It took a factory reset and complete erasure to pull it out of that one. Lost a good (paid) app in the process. I also learned the corporation can remotely erase the tabled whenever they like, and neither their security nor their hardware team were good thinking trough the consequences of their actions.
Second was a teams install used by me and some other people to videochat each other. One day, the school invites us to a meeting, after which teams decided the account now belongs to the school. Meetings with another institute were now impossible, as team's tiny brain could not allow the school and the institute to mix. For now, I deal by creating a new microsoft account for each meeting, and nuking the teams install afterwards.
My general attitude with microsoft is now: On non-MS browsers, delete all caches and settings when done, or use a different profile. On non-MS OSes, delete any login account they touched. When using any MS system like edge or windows, require different physical or virtual computers for each identity, they will leak into each other.
That's the kind of results Google should be surfacing, but it lost the game, it is so useless now for precision searching.
You can buy a good mini-pc for a couple hundred bucks and its much more powerful and flexible. You can run windows or linux etc and hook up any keyboard, controller, remote, and do whatever you like.
Nvidia Shield was great, but they upgraded the user interface and shat ads all over it.
This is not true if it is a Google Workspace (or whatever they are calling it now) account. Learned this the hard way when getting YouTubeTV. To be fair, it was just a couple of hours of frustration and annoyance but still, for whatever reason, the workspace accounts that you pay for are second class citizens.
I have seen this on HackerNews multiple times. I bought a Google Pixel this past week and set it up. I have not logged into a Google Account. Maybe if you give the phone internet access during setup, it doesn't give you the local account option. But I can attest that Google has not (yet?) closed the "offline account" loophole.
Product A adds a sign in. Product B from another team adds another sign in. Product C,D,E do the same. Each team has some special magic sauce that makes their system work better with their product, but worse with all others.
Now the corporate infighting starts, as management squeezes all these sign-in systems together, and everyone looses if any other but their system wins. So some compromise is created, based more on political prowess than technical requirements. The result is an API from hell, taking fragments from everyone, even if they conflict. Everyone pushes and pulls their existing systems until it fits in the compromise, trying to minimizing damage. Weird cracks appear everywhere.
we've all seen the organizational charts meme:
https://www.euroresidentes.com/tecnologia/noticias-internet/...
Remember how each organization builds a solution based on their organogram. Look at microsoft in the meme. Look at the sign in mess. Understand.
I predict strange, probably exploitable and surely unsolvable problems in the MS sign-in system for at least the next decade, just like their programming practices of the '90s had entirely predictable security consequences for a decade when the internet appeared.
Typical for Microsoft, reportedly: https://bonkersworld.net/organizational-charts
Realms is still in some kind of half subscribed, half not subscribed state and it still asks for my account's PIN for purchases but actually only accepts my kid's PIN. And every game warns me that my setup is questionable (store account doesn't match game account) even though it's exactly what Microsoft tells parents to do. Even Microsoft's own Minecraft app complains every 30 days!
I suggest this area for any web2 bug bounty hunters looking to make a fortune.
And MS login for work is a complete shambles. I have to do a tactical login to Outlook with a different work account to switch login when I try to use Azure as that's the only obvious way to move to a different org account. It's horrible.
Wrong!
It's even worse! You still have to log in with some MS account, but on top it's buggy, slow, laggy, and crashed a few times on me generating the world. What a disaster.
Also parental controls seems to suck in general on most services. Nintendo Switch seems to get it right for the most part.
this keeps everything from being comingled at the expense of maintaining all of those credentials
also, as a bonus, if you organize this by subdomain you can sort your email by it automatically since most emails from this stuff don't really need to hit your inbox
“Warning: You are about to login to Microsoft Atlassian Fogbugz Trello. Have you cleared sufficient space in your calendar, notified your next of kin, put your affairs in order, and taken your sedatives?”
It's once your sessions start expiring or you're trying to use the other services in meaningful ways that the journey begins.
We, as an Atlassian plugin maker, chose GitLab internally, and Notion, both because at least it was properly integrated and didn’t have the awful Atlassian ID and switch between apps…
It was something like two accounts existed in the system with the same email address and one of them had permissions, but we couldn’t sign in to it and the other we could sign in to, but didn’t have permissions and there was no way to grant it permissions.
I spent several hours with MS support over a few days while they tried to sort it out, reset passwords, sign in via different systems, etc. Eventually they recommend we create a new account.
I stopped working with Azure clients, instead.
I didn't bother porting my Mojang account to Microsoft, it was too stressful to use.
The UI of this is just as bad as the one that asks you to sign into MS account and upload all files to OneDrive when setting up Windows. It even comes back after some time if you deny it!
AD login is something that used to work well (10-20 years ago) but is now a complete clusterf*k. What was designed for logging into Windows NT workstations isn't what most users nowadays are expecting when logging onto web apps. Plus the UI full of antipatterns. Yet it's still the easiest for IT folks to manage.
In what way? Does the microsoft.com login system go down often?
The worst part is that some bot years ago signed up for the X-Box account using the same email I used for the Mojang account so converting the account first required me to take over the bot account with a password reset. But the bot set the account in up German and it's apparently impossible to switch the language settings for everything. I got most of it switched over (across four completely different configuration pages), but stuff like the emails are still sent in German. I'm pretty sure my account is going to be locked sometime in the future once they figure out that it was originally a bot account and there is no chance I'm going to be able to get my alpha Minecraft account back when that happens.
I guess it also doesn't make sense for them to maintain a parallel login system when the Microsoft one gets (presumably) millions of dollars of investment every year. Though Microsoft accounts are more complicated to use, with configuration being split across Microsoft, Xbox, and Mojang/Minecraft itself. And it seems they like locking people out for opaque reasons.
Very random example: SharePoint has a MS Word integration - you can open a .docx file from there, it opens in Word and you are actually able to edit the file on the server as if it was on your computer. At least in the older on-prem versions, this actually used the Word installed on your computer, not some web version. If you used a custom authentication provider, a little browser opened within Word and you had to log in there. But Word needed to "trust" the domain. On a personal computer, you could just edit the trust settings in some Word menu, yet the error message still said "your organization..." if you didn't.
Additionally, go to Accounts in Settings and double-check that you're not logged into any "work or school" accounts.
The one thing I can't stand is that if you log into a non-personal Microsoft account in an app, there's a dialog that is very confusing[1]. It asks if you want to use that account everywhere on your device, but there's a box checked by default to let the organization manage your device, a button that says "Yes", and what looks like a hyperlink that says "This app only". I always uncheck the box before clicking "This app only", but I wonder if keeping that box checked would still enable organizational device administration. It screams "dark pattern" to me.
1: https://i.stack.imgur.com/gmp00.png
---
Just to add a tip for others: If you want to use Edge for the Windows optimizations and PlayReady support for streaming services, but don't want to deal with all the annoyances, you can disable many of them via Group Policy[2]. For example, you can disable the "Search Bing in sidebar" option that shows up in context menus[3] that I always seem to accidentally click when I'm trying to search for something I highlighted. I also use Group Policy to set the default search and homescreen settings because then it won't annoy you with the recommendation to set it to Microsoft defaults every time it updates.
Firefox is my main browser, but I use Edge for streaming Netflix and the like because I don't get 4K playback via Widevine. It annoys me because Edge would actually be a great browser if the Bing folks weren't constantly trying to shove things down my throat and filling it with dark patterns.
2: https://learn.microsoft.com/en-us/deployedge/microsoft-edge-...
3: https://learn.microsoft.com/en-us/deployedge/microsoft-edge-...
Also, Google tracks you across all websites once you login to the browser (even if you don't use google login on them). If they weren't tracking you, using the browser profiles would be great.
outlook.com
Windows Store
xbox
Skype
Families
Office 365
I can't downgrade it to a personal account without deleting the account and recreating it, but there's not even a guarantee that will work. Deleting the account will also mess up family photo albums and other items. Photo storage is full but I'm also unable to pay for storage without adding a subscription to the account. It's so risky to try and fix it that I just had to migrate to a new google account, re-purchase all my android apps, and just ignore that account forever.
It was in fact super easy to just search my email Inbox for emails from Mojand and find the proof or purchase.
With MS I have 3 fucking accounts and not by choice, they bought Skype and Mojand and forced me into their super shitty system, I spent 30 minutes 1 year ago to migrate the Minecrtaft accoutn and more then 30 minutes a few weeks back to login back into Minecraft because I needed to detective my way to figureout what Microsoft account they connected to my Mojang purchase.
I hope in a few years someone leaks what greedy motives were behind this forced migrations, probably to sell more shit.
I don't understand why people think a microsoft account could ever possibly be more secure.
With smaller outfit's the L2 tech support might actually be having a line of communication directly to engineering, where in large companies there might be an L3-6 plus different product owners and escalation managers involved before a case gets in front of the engineering team.
Or maybe the bug's just going to languish and our friend Jeff here is going to be forced to create a new Microsoft account.
--
As far as AWS' products being independent products. I have the opposite view, as their products would be rather useless if they didn't interoperate with each other. How useless S3 would be if it couldn't talk to anything else!
Microsoft has been dealing with online identity almost since the consumer web exists. MSN launched in 1995, Outlook was the poster child of webmail, ActiveDirectory is the behemoth of enterprise user management.
I don’t see Hanlon’s razor relevant when it’s on one of their core competency. They at least committed to throw part of their users under the bus to pursue their goals.
I think some people are mixing up Hanlon's razor with "if it is bad, the malice part can't be on purpose".
Now, 4 years later I still get to choose wether I want to login in their tenant or mine everytime.
Microsoft solution? Change my email on the personal account.
Not kidding.
I have no idea where to report the issue to (Microsoft store? Minecraft support? Microsoft Windows support?), and having dealt with Microsoft support in a professional capacity I know that even if I do figure out where to report it that they will waste weeks of my time asking me to explain the issue and then claim it's working as designed without understanding the problem at all.
That's been a thing for a long time. I hit it when trying to share games with child accounts. IIRC, the high level process was:
- Set up child computer with a child account.
- Add parent account as family member on child computer.
- Set up a PIN for the parent account on the child computer.
- On the child OS account, open the Windows Store and log in as the parent.
- Log back in to the Windows Store using the child account.
At that point when the child tries to buy something via the Windows Store it should be asking for the parent's PIN, but accepts the child PIN. As far as I could tell it was authenticating the parent account with the child's PIN.When I ran into the issue, I could buy anything I wanted with the child PIN and it bypassed all restrictions.
I was so surprised by the way it worked that I spent an entire afternoon testing it. I got a prepaid credit card, set up fresh MS accounts for the parent + child, set up a clean OS install, and recorded everything using VirtualBox by using the on-screen keyboard to show the PINs.
At the time there was a bug in VirtualBox's video recording that caused it to record random garbage and I got so frustrated that I set it aside and never went back to it.
It seems like an auth bypass issue to me and it's been a problem for over 7 years. It's been around so long it's even made it's way from an unofficial blog into official MS docs [1]:
> As of Dec 25 2015, there seems to be a bug in the Windows Store sign in process as it may ask for your PIN code but it actually wants your family member’s PIN code. That is, at least at the time of this writing, use the PIN of the signed in family member even though it asks for your PIN!
1. https://learn.microsoft.com/en-us/archive/blogs/henrikn/shar...
This sort of scenario. Or a million others.
Windows is full of dark patterns, so I don't really know why I had even a modicum of doubt.
Between the aforementioned dark pattern with the buttons/not-buttons (they didn't even bother to vertically align "This app only" and the button), the not-a-question "do what we tell you" phrasing, the blank title, and a dialog that's overall around twice as tall as it needs to be, it seems recent Windows is unfortunately full of user-hostile and also disgustingly amateurish WTFs like this.
To any MS/Mojang folks lurking,- great game but the authentication merge was an unforced error.
FWIW, I had the same thing happen and found out the ban reason was "fraud (please insert phone number)".
I would frequently have to reinstall on PS5 to get it to boot, it would lose purchases constantly, and there is no cross play for mac hilariously because Mac doesn’t have a bedrock port, despite it having “Minecraft for education” which is based on bedrock.
Microsoft turned Minecraft into a steaming pile of garbage.
This is pretty much just best practice. When's the last time you could change your password without entering the original, short of a re-verification via email? Same idea here.
which, if the persons password is saved in their browser, would pass through to the website, granting a re-auth.
I got you now. I've been using 3rd party password managers (with a timeout for a forced reauth) long enough that I forgot when you let the browser do it it's not nearly so locked down.
I held out for a really long time, but a friend wanted to play minecraft with me so I finally caved. If they ask me to add a phone number I'll probably just abandon the account though, and look into piracy of the game I purchased.
Really makes me consider just not playing anymore.
Teams is written using web technologies so you're getting the same experience as the app.
Besides, there is a very satisfactory feeling when something doesn't work for whatever reason, you do a quick search and see that apparently you must edit some awfully named HKEY_LOCAL_MACHINE register or rename some <username>/AppData to .old (just had to do this yesterday, wild), and then, when the quick fix doesn't work, instead of trying to look for more fixes you just give up and start cussing until the VM is restored to a working backup.
Then they do absolutely crazy weird things!
I recently got a new laptop. My account is `adavis@<domain>.com`, my user name on my old laptop using that account is `adavis`.
What did Windows 11 do when I create my user on laptop. Oh it makes my user name `adavi`, yes it truncated my username.
After scouring the internet, trying a few different things to rename my account to no avail, nothing worked! Until I found a command to bring up an account management window that looked dated to the win 2k era ish (and can't be found via any settings window). It allowed me to create a local account with the name `adavis`. I then logged into it, deleted my `adavi` account then was able to associate my new local account with my Microsoft account.
Thankfully I only use it for some cross-platform testing and occasional gaming.
It is not quite a requirement, I have my Windows 11 Pro running just fine with no Microsoft account. They do attempt really hard to make it look like it's required though. Even going as far as showing a fullscreen app after Windows update that only has options for registering or login, but luckily Alt+F4 closes that abomination.
During the pandemic, a key security component of our remote work architecture was to use Azure AD Conditional Access to restrict users to login in M365 apps from AD joined laptops + some Inutne compliance rules.
A weird situation was that, for a new laptop, we could not login using a domain account, as it was not joined in our domain. We also could not create a local account to join it. Not sure how IT solved that.
Multi-accounts are really painful with most chat clients I have encountered. It sometimes makes me miss e-mail where the inside/outside distinction doesn’t exist.
Desktop Teams allows you to join multiple calls at once, and switch between them is easy.
Web browser teams disconnects you from one meeting to join another. The only solution is to open multiple browser profiles, each for different call, and then manage the 'mute tab' manually. Additionally, web browser edition has something to detect if tab is active, and will downscale / delay video stream if tab is not active. This is extremely annoying when you have meeting active on one monitor, and want to double check what is being discussed on another.
Saying all this, web browser teams at least works. Desktop one stops working because as the whole discussion here points out, accounts get mixed up. I can't join team meetings anonymously because desktop edition thinks I have an account, but when I try to login it tells me my account doesn't have Teams enabled.
Better solution: don't use M$ product, if you can. Despite the efforts and resources Microsoft spends in improving its products, languages, tools, they are just an enterprise company: very expensive buggy products.
[1] https://en.wikipedia.org/wiki/Microsoft_Windows_version_hist...
[2] All the backroom deals for Windows/Office licenses for state-use certainly helped in this regard, https://www.zdnet.com/article/linux-not-windows-why-munich-i...
Indeed and when I try it, it does surface it when I search for Does Nvidia Shield require an Android account? [1] For comparison, ChatGPT also gets it right. [2]
--
What GP is getting at is that Google Search breaks down often when you're looking for a very specific result, but one that is uncommon enough. Instead, you're often diverted to a "related" query result without them telling you.
An improbable search is almost impossible to do on Google. They will replace it with unrelated but similar results. Even when you specify a strong condition, it will just ignore it and return the exact opposite. It's no better than LLM hallucination.
There are pairs of words that are very similar, but semantically different. Like "latitude" and "longitude" or "first name" and "last name". Google's model can't make fine distinctions between related (like latitude and longitude) and semantically equivalent (like last_name and family_name). You search for a semantic match, it will give you a related result that is exactly not matching your search.
If I’m all-in on the Google/Android ecosystem, this is a positive! It works even better!
The alternative is that the people behind the Nvidia Shield are intentionally user hostile / acting with malice, in cooperation with Google?
The idea that the account requirement is positive or negative is a hugely subjective one. The fact is it’s needed. Whether it’s positive or negative is largely irrelevant. The fact should be surfaced.
I strictly use the local-only setup. I'm sort of OK if they still leave a relatively trivial backdoor to do this, but if they ever flat require an online account, I'm out, hard.
This is partially due to wanting to avoid the hassle and management of yet-another-forking-online-acct-IDGAF-about, but also because I have some machines controlling industrial processes (CNC machines, custom cutting machines, etc.) that I keep entirely off any network for security & safety reasons (yes, moving anything to/from those machines is all sneaker-net; simple, works, and my shop doesn't yet have the scale to justify that kind of networking/security/admin overhead).
I just hope that MS engineering is not stupid or powerless enough to allow MS marketing & MBAs to fully kill off the local account.
This entire attitude of exploiting customers by requiring spurious internet accounts & connections is making me start to think that the Internet is all a huge mistake. If that approach takes over, the world will literally be worse than before the Internet in every important way (and there are some solid arguments that it already is worse).
That's just.... Insane. This is going to be a disaster. I'm so sorry, Windows users.
Sounds like a huge pain to deal with. Why not switch to Linux and be done with it? Genuine question.
Plus, at the outset of another startup, we decided to go Open-Source everything, and tried to setup a real-time version of Linux and the CNC control software. All of it supposedly up and running with only a few dozen steps to setup in the people supposedly running it. Despite decades in networking and a bit of Linux experience, I quickly got swamped in the massive undocumented bugs in setup/config/complile, and brought in a guy who had a full-time Linux shop, and who I knew from working with him previously that he was very good. He thought 'it's a new version, but no problem'. A month later, we still had nothing running and the investor/partner pulled the plug. So the swamp of poorly-documented / undocumented / mis-documented hiccoughs literally killed that startup — death by 1000 cuts.
Sure, it is probably better now, 15 years later. But so is this environment, UNLESS they tie it to another online acct.
So, basically, I'm pretty much now in the business of slinging atoms instead of bits, and the overhead is no fun, and just not worth it (yet). Plus, the overhead of working around the MS carp turned out to be pretty small. Just disable the Wireless at the right time in the W11Pro install (I think it is worse in teh Home version).
I know valve have done great stuff but is it good enough yet to run everything on a AAA game on 4k ultra with hdr, gsync and 144hz?
At that, it still excels and is no mistake. The problem is all the people using it for money.
Someone said a long time ago that "The love of money is the root of all evil".
I'm not a follower of any particular religion, but that guy sure got it right on that point! Also, the only time he was recorded being violent was when he kicked the money-changers out of the temple.
How do we kick out the money-changers from the Internet?
Back to the roots of info transfer... it seems the tagging devices+apps tell us that we have achieved critical mass of node/relay density for an underground mesh network to work, if we can get enough people to run it . . .
They are pushing more and more people into the perception of renting a experience rather then owning a device. Its great money for me to help people figure all this out though.
[1]: https://www.scottrlarson.com/publications/publication-transi...
[1]: https://www.scottrlarson.com/publications/publication-transi...
They can either remove that policy from their azure AD, or remove the machine from the azure ad.
Or update their policies to allow for azureAD joined machines.
If I could make one law get passed, I would outlaw algorithms on social media feeds (edit: and search engine results). Let them collect the data, let them target ads. I don't think those things are inherently harmful, or at least, no moreso than the old ads and surveillance.
But the seizing and algorithmic manipulation of the feeds, with the accompanying incentive that the whole thing fails if it doesn't turn a profit, is far more toxic than the gatekeeping of the old media emperors. The great promise of the internet in the 90s was that consumers of internet media would have complete control over our feeds, and get only the things we want and demand.
We have received the exact opposite, because people with money want to put their money to work, rather than work.
The main problem is that randomly, Teams invite end in some "an unkown error occurred" and when this happens there's no recourse. It never happened with Zoom, Jit.si, Goto Meeting, Google Meet or whatever else I've used.
The absolutely worst of all is WebEx, fortunately it's rapidly disappearing.
More flexible, yes, but are you really getting more powerful than an A15 for that price, especially when running a general purpose OS?
That last point is really hurting why media PCs disappeared: you’re paying considerably more - a whole number multiple - for an experience which isn’t designed for a TV, and in return you get the fun of playing sysadmin when you’re trying to relax. Most people are not going to pay a significant premium so they can deal with drivers and trying to figure out why their HDR isn’t working. Device lifetime theoretically could counter that out but I’m skeptical that hardware won’t be what sets the timing for that in either case, and the dollars per year metric isn’t favorable there.
There are certainly better push-button solutions on the market, but arguing in the AppleTV's favor for performance is probably a phyrric victory at-best. If you want an AppleTV, get an AppleTV - if you want a streaming box for your ripped Blu-Rays and legally-dumped retrogames, you can build it yourself for roughly the same price.
The cheapest one Google knows about is an AliExpress no-name brand at $159 and that’s because it includes no storage or RAM, and uses a 3750H which benchmarks at less than half the speed. Once you add memory, it’s over $200. It does match the Apple TV on 4K@60 HDR support so I’d assume it must have hardware support.
Amazon has a couple of off-brand Intel devices, also around $200 for around half the Apple device’s performance.
Again, if you really want a PC you certainly can make it work but the reason it’s unpopular is that you’re paying a lot more – this is starting at 150% for hardware which is unlikely to last as long – and you then have to support a full PC, buy remotes, etc. If you enjoy that as a hobby, sure, but it’s hardly surprising that most people buy something which just works out of the box.
Judging by the threads on those proprietary embedded devices, I think my setup passes the "just works when you want it to" test even better than those appliance things, which market an illusion of stability but are doing the same mutable update dance behind the scenes (with the added complication of corporate whims).
As someone who started using desktop Linux and supported it professionally before the turn of the century, yes, I’m aware and you’ll note that I never claimed otherwise. The reason I mentioned general purpose operating systems is that they’re not optimized for non-keyboard/mouse UI and you’re more likely to get in a situation which requires more work to sort out via the CLI.
The other concern I raised was drivers. Support for hardware video decoding, colorspaces & depth, high-quality sound, etc. is certainly technically possible but also something which not-uncommonly ends with angry rants. If you are passionate about open source and eager to take on that responsibility, great, but it’s not a popular choice.
Setting that all up on PC is much more of a chore.
If all you want is netflix and youtube then of course a 50$ chrome stick is fine.
Having to use a mouse and keyboard is a pain point for me when I use my desktop on my TV from the couch. For the mouse I use the trackpad on a ps5 controller, so the mouse isn't so bad.
Possibly you could: * Not require passwords for everyday operation of your computer * Boot into some sort of launcher designed for televisions * Have a fairly narrow set of apps and services that work well with your setup. For example I don't know how you'd use Netflix or Disney plus with a remote on Linux.
We also have an old laptop attached to the TV. We set that up in the lockdowns so we could use a webcam on the TV and a wired microphone on the coffee table to "get together" with friends and family, still use it occasionally for Dungeons & Dragons with friends who live too far away to visit often. The Apple TV doesn't support webcams, but wins at everything else, hands down. Even for desktop-y stuff, streaming my Macbook or my girlfriend's iPad to the Apple TV is less hassle.
Desktop ergonomics just don't work on the couch, at least for us, even with a nice-ish wireless keyboard with touchpad. Having a touchpad remote with just four buttons that have very predictable functions and a simple mobile-ish UI is nice, even to me, and I'm a desktop power user otherwise. Desktop OSes are for work, school or uni, most people aren't inclined, encouraged and/or enabled to explore and play in those, so they don't get them the way desktop power users do and tend to expect everyone else to, or the way people get mobile UX.
If you want something nearly everyone can pick up quickly, even older children and some seniors, make it touch-based, responsive, give it proper apps and the same core animations mobile phones have and you're 80% there.
That’s about it though.
Admittedly I only have local media and YouTube (via a Kodi Plugin)and don't use any streaming services so Kodi fulfils my needs perfectly.
1. https://kodi.wiki/view/HOW-TO:Autostart_Kodi_for_Linux
2. https://kodi.wiki/view/Remote_controls
https://www.amazon.com/Microsoft-Wireless-Media-Keyboard-N9Z...
https://www.amazon.com/Logitech-Wireless-Multi-touch-Certifi...
https://www.amazon.com/Rii-Wireless-Bluetooth-Backlight-RTi8...
Only "proper" solution is to /not/ sign into your MS account when seeting up the new machine for the first time. Create a local account with the name as you want it, and then only afterwards link it with your MS account (if you have to).
Only problem is, latest Win11 installer does not allow you to create a local account anymore at all. So you need to install Win10, do the work-around-dance, and then upgrade to Win11. I only relaized this after halway through my most recent format.
Every time when I ssh into one of my other boxen, I have to remember now to go 'SSH myname@ip' else windows helpfully defaults to 'mynam@IP'
In the "Let's connect you to a network" page, use these steps:
* Use the Shift + F10 keyboard shortcut to open Command Prompt.
* Type the following command to release the current network configuration and press Enter: oobe\bypassnro
Note: The command is a single phrase without spaces.
Note2: This will reboot the machine and restart the installer again (why?? because fu for not wanting a MS account that's why)
You can create a file ".ssh/config" in your user directory, just like under linux, and inside of it put "User myname", and ssh will use that as a default and you won't have to specify it with @ everytime.
Install flight simulator on a Win10 PC with local login only and launch -> sign into an xbox account -> after you enter your name and password, you get a dialog box where you have to agree to sign your Microsoft Account on that PC with two dark pattern options that lead to the same result.
I couldn't find any combination of group policy editor, registry, and services.msc around it. You can either close it and lose access to the game you just paid for, or proceed and then you get your account signed into email and a bunch of other crap you dont want and have to spend hours getting rid of all traces of that account in your system(but it's never 100% gone). Only way to bypass it is to buy the game through Steam.
Between MacOs Linux and Microsoft, Microsoft has the last respect for you as a user and nobody should use it if they don't have to.
I suppose they might make it mandatory unless you have some special version of Windows which is hard to buy (like LTSC). But make it too hard they risk that market. Anyway, now bypassing it involves opening a command prompt window, only the more technical users will do so, and that’s a small enough minority they probably aren’t missing much.
I know it is a pipe dream but I wish they could be forced to sell this to the general public.
Sounds more likely to me that they'll just abandon those market segments.
Not a Windows user, but that wording of the setting is making me irrationally angry
It really, really irks me.
"The New Goliaths: How Corporations Use Software to Dominate Industries, Kill Innovation, and Undermine Regulation"[1] looks like a good book on the subject that I plan on reading.
[1]: https://www.amazon.com/New-Goliaths-Corporations-Industries-...
My Kodi box boots straight into Kodi. I have a mini wireless keyboard on it (Rii X8?), but the alphanumeric functionality isn't particularly used and it could just as easily be a video game controller or even an IR remote.
There is no "situation which requires more work to sort out via the CLI", beyond when I deliberately choose to make changes to the system. If I ever did want to pop out of Kodi and run a general desktop + browser - say for sports streams - then the additional input hassle would be due to doing something I couldn't do with an appliance anyway. You can't really characterize this as a drawback.
And sure if some driver functionality doesn't exist, then obviously you can't use it - you set your expectations to what is available and how much you want to tinker. And the real answer to "angry rants" is to use an operating system with reliable change control, so that if you start tinkering with something, it cannot end up in a broken state when you want to use it to relax.
I have looked into buying LTSC. Apparently you need a business (I own a “shelf” company which has never done anything, but legally it counts), and a Microsoft volume license agreement. I looked into the later. Supposedly there is this trick where you order all these useless-but-cheap Identity Manager CALs to cheaply meet the minimum order requirement for a volume license. But I got a bit stuck working out what to order (or even if it was still available through resellers in my country). I lost interest at that point.
Also I find it a bit disingenuous when people argue for the "less expensive" options that put you at the mercy of streaming companies. My amd64+Kodi+zfs+VPN setup certainly isn't the cheapest, but neither is a corporate puck with several monthly fees for streaming services. If one wanted to be entertained for the least money possible, I suspect that would just consist of using your current laptop/computer running a general purpose OS to play dodgy streaming sites. But most people seemingly want something more than that (which ties back in to my first paragraph).
So I gave in, switched to Plex, paid for a Plexpass lifetime account, and bought embedded devices that could stream content off my server.
I have way less flexibility now that I’m on an AppleTV 4K. I also continue to get occasional headaches (e.g. recently the remote control randomly stops being able to control the volume), but the size of the headache is limited to pulling out a different remote control / turning all the things off and on again. Mental effort not required.
I have a laptop that goes into the 4x2 HDMI splitter, and I occasionally whip that out if there’s a real desperate need. But it’s the absolute last resort. It’s just easier to use the ATV.
It’s not that I lack the ability to produce a better PC based solution today, it’s that I lack the interest, and the $200 ATV is good enough that I’d rather throw money at the problem than time.
> dont see the benefit of these android based TV devices or Apple TV anymore.
My point was simply that an Apple TV is significantly cheaper ($100-120 vs. the $200+ PCs people mentioned) and it has roughly a factor of two better performance. Now, it’s inarguably less flexible but most of that flexibility doesn’t help with things many people want to do, which was the original point: people buy these because “spend less, everything you actually use just works” is actually a pretty good sales pitch.
This info is publicly available so more detailed info should be easy to find.
Telemetry is a bit of a non-issue for many national security applications-they run on special air-gapped networks with zero direct access to the public Internet, Windows can try to phone home to Microsoft all day long, it’ll never get through.
And disabling telemetry doesn’t require LTSC or Enterprise G. All Enterprise, Education and Server editions support “Diagnostic data off” telemetry level. Even if that’s not the default, most enterprises who want that will build their own install images with that setting configured.
Enterprise IT is conservative and full of strange politics that make it really dangerous for an admin team or it department to stick their head out and do something independent other then follow the "mythical industry best practice" and MS is extremely good at manipulating what gets considered "industry best practice" to their advantage and then give just enough discount on the more visible parts of the costs to look cheaper.
And it's a open secret that individual employee productivity don't matter all that much in the kind of back end work where a PC was ever a feasible tool, as what really counts for profitability is the non-pc using frontline staff's productivity, who is far more likely to be issued either no computers or mobile phones or tablet then wintel laptops.
They now are giving teams (slack knockoff) a free dialing number so it now can be used for phone conferencing without non-organizational people.
Onedrive gives you 1Tb of syncable storage per user, and 1TB per user pool for shared office resources.
I spent years as a google apps advocate, but seriously for the money, no one touchs what MS is offering right now. Google had MS hands down 10 years ago, and let google apps die on the vine. It is a damn shame too, because they were the only ones that have anything comparable.
On paper microsoft absolutely has the best offering. The ms365 suite has everything anyone could ever need. But, in practice it feels more like a downgrade than an upgrade. Teams does everything, and all of it just as poorly. Office does everything, but the web version and collaboration features are so far behind google they are not comparable. Sharepoint and onedrive seem superior to google drive, but in practice there are many papercuts and people struggle to understand where to put documents and how to properly share them.
What microsoft seems to lack is caring about user experience as they slather feature layer after feature layer on top of their products. What google seems to lack is incentive to actually meaningfully improve their product, because I couldn‘t tell you a single meaningful feature they added to g suite over the last five years.
That's the problem of selling something to the supervisor and not the actual user. MS has had that corporate world as a cash cow for three decades now. They don't care about the end user they just care that their product looks better in the slide that compares it to the best alternative.
You're right, for the money MS gives the user a lot of fairly crappy products (other than the office desktop suite). Google was positioned to own this, and they let is drop. It shows what it means to be a product driven company (MS) vs. whatever Google does nowadays (milk search ads?).
There are teams of people in MS whose only job is to think about how to package something for sale. If Google had a single person doing that they would have beat Slack before it got huge, and could have owned office collaboration software as it all moved to the web.
And I've never found any documentation as to whether shared OneDrive folders count against the owner's quota, all of the users with permissions quota, or the sharepoint quota.
[0] https://learn.microsoft.com/en-us/office365/servicedescripti...
But the basics each user gets their own quota of 1 to 5tb,then there is also a shared quota (share point, Ms group storage, powershell online environment, dataverse, etc... ) of 1 to 25tb + (x size per user) the size per user depends on a multitude of factors.
I did not mean to imply that users limits are connected to the shared pool, it is in addition to the user quotas.
Fuck teams, though. I will leave this company before migrating Slack into teams. Actively recommending that product is nothing short of professional negligence.
It's just too good to ignore.
For all it's terrible bugs and login issues, is there even alterative with similar functionality that would be as "user friendly" (as in: non-tech people would know how to use it as well as they use Microsoft garbage?).
I literally can't think of any alternatives that comes close in functionality OR has the same ease of use for non tech people and wouldn't waste even more time.
We recently discussed this "shadow work": https://news.ycombinator.com/item?id=34612697
Mac is not an alternative functionality to: Teams, Outlook, MS Office, etc? It doesn't solve the MS crappy auth system, it doesn't give (large) businesses the same functionality that MS is giving them.
ReactOS isn't stable enough even in a VM right now – but the progress is nice, and I hope it will be a viable alternative for embedded applications (like ATMs or factory automation stuff). Maybe consumer use one day, too?
I leave my personal Windows 10 desktop running for about a month at a time so I don't have to reopen 5 different windows and arrange them across three screens for uni work every evening. It works fine.
Mind you, if it was a Mac I'd not even have to reopen or arrange them after restarting the machine - they'd still be there. Although my work Mac loves to randomise which display gets which windows and desktop background... And randomly pan all bluetooth audio to the left ear once a week. I guess all OS's have their issues.
My Win10 Home desktop downloads updates when I'm not looking - and sometimes when I'm actually using the thing - and then reboots all on its own. I have no control over this; there have been occasions when the reboot has happened while I was working.
It happens roughly once a week.
Outlook, Teams, Chrome, COMRAD (radiology RIS), Spotify and InteleViewer (DICOM viewer). Without restarts Spotify stops working, the software loses track of what day it is (it assumes the day prior) and things get slow or unresponsive.
Maybe it’s the software and not the OS. I run all those except COMRAD on a Mac ok though.
Mac and multi display and window location is a special hell. My father is a heavy Photohop user and palette organisation is a daily battle with multi screen. When screens wake up windows and palettes reorganise if the system detects one screen and not two briefly. It’s a big drain on productivity.
You more or less need to be a dev-ish person to prove IT is at fault. The lusers have to live with the unplug the computer and reboot workarounds.
If my org doesn’t give me a supported way to do absolutely necessary thing X, then I’ll find my own way to do it.
This, at least, is a thing I have never even had to consider as a remote possibility on Linux.
Apple is really bad too, but there not as bad in the dark patterns market at least in the OS. But they are way strict with their walled garden approach to everything so I wont support them either.
Linux can be buggy at times, but I feel much safer using this OS then I do Windows or MacOS because Microsoft and Apple don't really seem to care to much about the ramifications of their end-user hostile decisions.
Which is like, wow, half a mil a month, but... also alarmingly little!~
Apparently the backward compatibility monster is not the size it used to be?
Now I understand why Win11's designers used Macs... wow the moat got small
you can try to find as many edge cases,
but at the end of the day I just log into the account that's inside domain and everything:
email, teams, network accesses, auth thru web apps goes thru that domain account
Because I tried to do that recently with O365 and I literally couldn't move my subscription without killing the old one and creating a new one.
Every other software service I use somehow managed to make it easy: fill in the new billing details. Done.
But not Microsoft. Billing and fulfilment details are on different pages, there's no obvious way to get from one to the other, and if you want to change country you can't.
Superb.
Even having physical copies of The Economist follow me, with the same subscription, was easier.
You can also use any of various other products that compete with them (Google Apps, iWork, Zoom, etc).
Just because MS makes a specific package that businesses like doesn't mean that they can't use something else if MS is becoming more of a problem than they're worth.
Source: https://lazyadmin.nl/it/how-to-stop-automatic-restart-win-10...
This is also related to trying to control the circulation of replacement parts by attempting to force independent repair centers to regulate how parts are distributed. Apple takes more of a "You don't know what you are doing, so we have to guide you in the right direction" approach that doesn't sit too well with me. Apple can be wrong, a lot, about how their decisions effects people's freedom to decide how to implement there own security and ways of retiring devices. Apple should be in the business of making hardware and making it usable. Not being a parent, deciding how people are going to use and secure their devices. Maybe leaving that to an impartial organization that works with apple. Too many conflicts of interest for me.
Awkward… no, I haven’t dug into it at all. I now will.
It's not an argument not should it be used as such.
It’s not an argument nor should it be used as such.
Maybe they all need nonstandard software? God forbid, maybe they need administration permissions, but the org doesn’t want to give it to them, so they end up calling in every other day to get something unlocked (I know that’d be true for me).
Maybe it’s the problem solving skills of the IT team when it comes to mac, so people keep coming back with the same issues (good ones are Outlook/Teams being permanently broken, or VPN not connecting).
On the whole, I’d steer away from any explanation that would require all 500 mac users to be idiots.
MS makes it very easy to secure and admin at massive scale. You can roll out policies and updates to hundreds of thousands of machines with like 1-2 admins, and the other 8 IT people manage 200 Linux and Mac machines.
And everything just works out of the box with like... 3 lines of PowerShell.
You can replicate some of it with Ansible, sticky tape and a few spare weeks, but it's not the same at all.
I'm actually Linux admin, grew up with open source and spent my career serving pages and automating myself out of a job. I dislike Microsoft as much as the next guy, but for enterprise use they are _next fucking level_.