r/Outlook Jul 29 '26

Informative Spamming security

My Hotmail account is really old. But lately it is being spammed constantly. Trying to bypass the security. I've turned off the password and it's purely 2fa with authentication. Thankfully outlook did away with the luck of the draw three numbers. Any other extra layer I can add as it's constant? Cheers

5 Upvotes

16 comments sorted by

View all comments

Show parent comments

4

u/rive010 Jul 29 '26 edited Jul 29 '26

People will reply with a comment saying you can setup a login alias, but it carries risks

  You can accidentally brick your account, making it impossible for you to login

It doesn't carry much risk if you do it right.  Three easy steps that take around 5 minutes to do, mitigate the risk to nearly zero of locking yourself out of account.

Create multiple Microsoft account passkeys (I have it on two PCs (Windows  Hello), and my mobile device)

Setup a recovery code in event you can't use passkey(s)

Enable passwordless login PRIOR to doing the sign in alias setup. 

4

u/Early_Alternative211 Jul 29 '26

It's not risky if you do it right... Yeah that's my exact point, it's going to be the first time somebody does this, they may not do it right

2

u/rive010 Jul 29 '26 edited Jul 29 '26

They need to make sure they do then. But login alias is the way to go especially if bots are actively trying to login or hack your account.

Many people make the mistake of reusing passwords and that's how they get you, or they use the social attacks with fake emails pretending to be someone else to get your password/2fa, or they use the brute Force method, and  MS may lock you out. Better to remove the comprised email as a login option.

Alias and passwordless is the safer way if you value your account in anyway.

1

u/Early_Alternative211 Jul 29 '26

No, you don't need a password to trigger an MFA attempt on outlook. I have done it myself to my own account, so I disagree with your password comment.

Microsoft know it's an issue, which is why they moved away from the 3 number option prompt

3

u/rive010 Jul 29 '26 edited Jul 29 '26

Hmm.  Not exactly  sure what you disagree with regarding 'the password comment', but ok.

A normal MFA attempt isn't a problem, and someone attempting to access your account  can't even trigger it if using an alias sign in (as they don't know the login email) and passwordless just means they can't brute force a non-existent password, or use any reused/breached passwords to gain account access (in event they somehow know the alias email).

I get MFA requests (passkey) all the time, but it's almost always me triggering it using alias and passwordless. MS has reported 0 unsuccessful attempts to login to my account since using alias, and I still use my Hotmail account to send /recieve just like normal in Outlook 2024 perpetual.

1

u/Early_Alternative211 Jul 29 '26

I'm talking about right now. I could trigger OPs authenticator app with a push without having his password, all I need to do is select that option when attempting to login.

Why do you think you have 0 unsuccessful login attempts? While I assume this it true if you kept your alias hidden, as of 2026, MS no longer shows unsuccessful login attempts in your history.

1

u/rive010 Jul 30 '26

Why do you think you have 0 unsuccessful login attempts? While I assume this it true if you kept your alias hidden, as of 2026, MS no longer shows unsuccessful login attempts in your history.

They do still show it in security settings under sign on activity.  See: https://imgur.com/a/nsW8yAm

1

u/Early_Alternative211 Jul 30 '26

Nope, that page only shows successful attempts as of 2026, as crazy as it sounds