July 20, 2026
Here’s what this company found whilst looking on Microsoft’s website
I was doing some research the other day into desktop authenticator applications.

By Alex Hughes
3 min read
Nothing particularly exciting — I was simply curious about the options available for people who don't want to use their personal phones for multi-factor authentication (MFA).
As you'd expect, my search eventually took me to Microsoft's Edge Add-ons marketplace.
Along the way, I came across an article from a UK IT support company called IT Desk.
It wasn't the article itself that caught my attention at first. It was the story behind it.
The company had been helping one of its customers answer what seemed like a perfectly ordinary question:
"Can we use an authenticator app on a Windows computer instead of a personal mobile phone?"
Instead of simply recommending the first result they found, the engineers started investigating the available options.
What they uncovered wasn't evidence of malware or a scam.
It was something much more interesting.
It was a lesson in how easily we trust what we see online.
It Looked Completely Legitimate
According to the article, one browser extension immediately stood out.
It appeared to have everything you'd expect from a trustworthy application.
It used Google's familiar Authenticator branding. It was listed on Microsoft's own marketplace. It had a polished description. It displayed what appeared to be a "Verified Add-on" label. It even had a perfect five-star rating.
If you'd shown me that page without any additional context, I'd probably have assumed it was perfectly fine.
I suspect most people would. After all, it's on Microsoft's website.
Surely someone has already checked it?
That assumption is exactly what made the rest of the story so interesting.
They Did What Most People Don't
Rather than recommending the extension immediately, the team kept digging.
The article explains that they started asking the kinds of questions good IT professionals ask every day.
Who actually developed it? Where do the links lead? How mature is the software? Do all the trust signals actually mean what they appear to mean?
None of these questions were based on suspicion.
They were simply part of the process. And that's something I think many of us forget.
The best cybersecurity professionals aren't necessarily the most cynical.
They're simply the most curious.
The Details Were More Interesting Than the Headline
As the team investigated further, several details stood out.
Clicking the apparent verification information took them to a GitHub repository rather than what many users might expect to be a Microsoft verification page.
The extension was listed as Version 0.3.0, suggesting it was still relatively early in its development.
The publisher name shown on the marketplace appeared to be "Verified Add-on."
Again, none of this proves anything is wrong.
In fact, the IT Desk article goes out of its way to avoid making that claim.
The extension may be completely legitimate.
The developer may have had perfectly reasonable explanations for every one of these observations.
That's not really the point.
The point is that every single one of those details required someone to look beyond the first impression.
Most people never do.
We Trust Interfaces More Than We Realise
Reading the article made me think about how much of modern cybersecurity has become psychological.
We don't evaluate software in the same way we might have twenty years ago.
Instead, we rely on visual shortcuts.
- A familiar logo.
- A professional-looking website.
- An official marketplace.
- Five-star reviews.
- Words like "verified."
Those cues help us make quick decisions.
Most of the time, that's perfectly reasonable.
The internet would be exhausting if we questioned every single thing we saw.
But attackers — and sometimes simply misleading listings — understand exactly how those trust signals influence our behaviour.
That's why it's worth slowing down occasionally.
This Isn't Really About One Browser Extension
The more I thought about it, the more I realised the article wasn't actually about the extension at all.
It could just as easily have been about:
- Mobile apps
- Browser extensions
- AI tools
- Password managers
- Chrome extensions
- Productivity software
The lesson stays the same.
Official-looking doesn't necessarily mean officially endorsed.
A familiar logo doesn't automatically mean an official product.
A five-star rating doesn't always tell the whole story.
Even software hosted on trusted marketplaces deserves a little scrutiny before you click 'Install'.
Good IT Isn't About Being Paranoid
One thing I appreciated about the article was its tone.
There were no dramatic accusations. No claims that the software was fake. No headlines declaring a massive security threat.
Instead, the company simply explained what they observed and encouraged readers to make informed decisions.
That's refreshing.
Cybersecurity doesn't always need to be about fear.
Sometimes it's simply about developing better habits. Taking another minute. Checking another detail. Asking another question.
Why This Matters More Than Ever
We're entering an era where software is easier than ever to publish.
AI can generate convincing branding in minutes.
Professional-looking websites can be built in an afternoon.
Review systems can be manipulated.
Trust signals can be copied.
None of that means we should become suspicious of everything. But it does mean we should be a little more intentional about what we choose to trust.
The engineers at IT Desk weren't trying to prove that a browser extension was dangerous.
They were demonstrating something much more valuable.
Good security often starts with curiosity. And curiosity is something every one of us can practise.
Final Thoughts
That customer probably never realised their simple question would lead to an article like this.
I certainly didn't expect to spend part of my afternoon reading about a browser extension.
But I'm glad I did.
Because the biggest takeaway wasn't about Microsoft. Or GitHub. Or browser extensions.
It was a reminder that the safest people online aren't the ones who know everything.
They're the ones who pause long enough to ask:
"What am I actually looking at?"
Sometimes, that's the most important cybersecurity skill of all.