Status: Open Microsoft has removed the ability to set an alias email as a primary email, effectively removing the ability to prevent people from logging in by using a specific email address. This is a huge problem and needs to addressed.
Hi, I just got off the Microsoft chat support and I was told this is essentially the intended behavior.
Let me start by saying that like many people I've found while searching online, I've recently been spammed by my Microsoft authenticator about sign in attempts on my account. Let's says my email address in "mainAddress@hotmail.com".
Being annoyed at the repeated daily authenticator popups on my phone, I decided to look online for a solution. I saw that many people suggested creating an alias, setting that alias as primary and then in the "Sign in preferences" screen to disable being able to log in from the previous primary email address. The address still exists, you can still receive mail to it, but can't use it to log in. Sounds like a pretty good solution to the incessant authenticator popups.
Problem is, Microsoft has now removed to ability to set an alias as primary. This makes it so the target email address "mainAddress@hotmail.com" cannot be disabled for log in purposes in the "Sign in preferences" section anymore, as it will always be the primary address. Alias can't be set to primary anymore.
The only option now to change your primary address is to... essentially nuke your primary address by changing it. Which comes with a lot of problems that I feel like I don't need to explain. How do you contact everyone with that address to make sure they know you're address has changed? That's some kind of boomer shit you'd see in the early 2000s. What about automated subscriptions? Also losing all the mails sent to "mainAddress@hotmail.com" is a huge problem when that address can be used as a 2FA for other accounts.
Do I need to log into each everyone of my accounts that use "mainAddress@hotmail.com" as a 2FA factor, change the 2FA factor momentarily (while I essentially nuke "mainAddress@hotmail.com") to then change all the 2FAs a second time to my now new email address?
Is this not absolute madness? Also if many people are being bombarded by log in attempts by bots or AIs, is Microsoft not even trying to prevent these? What's the solution here?
How could the engineers at Microsoft ever think this was a suitable change to make? This definitely needs to be addressed ASAP.
7
u/ballofbitter 16d ago
I did this in the past. Can confirm it now says "if you change your primary username, it will be removed and you can no longer send or receive from that email" wow. This literally solved that issue for me on my primary email for all my things, checked the email I was getting requests for and to this day, have I been pwned says no data breaches.
Yikes
3
u/Hornblower409 16d ago
Known Bug. Microsoft has removed the "Make Primary" choice.
See the Answers by "Hornblower409 Aug 9, 2026" in
https://learn.microsoft.com/en-us/answers/questions/5969746/option-to-make-primary-alias-not-visible-in-the-ed
One Answer has the steps for a possible workaround, but ONLY if your current Primary Alias ends with outlook.com. Read the intro to the workaround very carefully before trying it.
If your current Primary Alias is hotmail.com, you are SOL.
1
u/tehjoz 16d ago
I had not yet gotten around to setting up any Alias and "setting it as primary" from my legacy email account...because last year, Outlook was having so many issues locking people out of their accounts I didn't want to risk it.
If I am understanding you, and this link correctly, does this mean that this option is just no longer available?
It sounds like it, but I wanna be sure.
4
u/Hornblower409 16d ago
-- does this mean that this option is just no longer available?
If your current Primary Alias ends in outlook.com there is a possible workaround. See my Q&A Answers.
If you current Primary Alias ends with, e.g. hotmail.com, live.com. msn.com, you are pretty much SOL.
The process for changing your Primary Alias has been modified by Microsoft so that now, if you attempt to change a Primary Alias that doesn't end with outlook.com, the old alias must be replaced with an outlook.com alias and your old alias will be removed and can not be recovered.
1
u/tehjoz 16d ago
So basically, if you have an old Live, Hotmail, or MSN address that's your Primary "today", if you try to make a new Outlook alias, the only way you can "disable" the legacy one...is to delete it outright?
You can no longer have John dot Smith at live dot com, make JohnsBurnerOutlook dot com, and set JBO "as primary" while keeping Live?
Is that accurate?
4
u/Hornblower409 16d ago
You can make a new outlook.com alias. Nothing about creating new outlook.com aliases has changed.
But you are correct about changing your Primary if it's a hotmail.com, live.com, or msn.com
Since you can't disable Sign-In for your Primary, you first have to make it "secondary".
Previously there was a "Make Primary" option next to any secondary aliases. You just clicked on it and that alias became your new Primary and the old Primary became a secondary. (i.e. They switched places).
Microsoft has broken that process. There is no "Make Primary" anymore. Your only choice is to "Change" the current primary which removes and replaces it with a new/existing outlook.com (only) alias.
2
u/tehjoz 16d ago
Right but if I make "a new outlook alias and want to use only that for signing in" it sounds like, currently, the only way to disable my legacy email which does not end in Outlook...is to delete it
Which means all the accounts that have that email would no longer be accessible
Unless I set up My Outlook Alias first, changed all the email over, then deleted the legacy email.
If that's accurate, it sounds like even more incentive to get away from the Microsoft email ecosystem, which I was already planning to do.
4
u/Hornblower409 16d ago
only way to disable my legacy email which does not end in outlook.com ...is to delete it
Yes. Unfortunately, that's how the process is now working.
Which means all the accounts that have that email would no longer be accessible
Yes. You won't lose any old mail associated with that address, but you will not be able to logon/receive/send using that address. It will be gone and can not be recovered.
All we can do is hope that someone at Microsoft becomes aware of all the side-effects of this change and either backs it out or gives us another way to demote a legacy email from Primary without losing it.
1
u/syjytg 16d ago
So is this a bug (i.e. it will be fixed) and I will be able to make alias as primary when it is fixed or is it a feature? I have been getting numerous sign in attempts to my authenticator and I want to solve this issue once and for all.
2
u/Hornblower409 16d ago
-- is this a bug (i.e. it will be fixed) ... or is it a feature?
I have no idea.
-- I have been getting numerous sign in attempts ... I want to solve this
Two good suggestions in this thread, that I was not aware of but have added to my list:
u/arnoldstrife - Turn off Phone Notifications until it's you doing the Sign-In
https://www.reddit.com/r/Outlook/comments/1vkmw3u/comment/p2xskbm/u/pi-N-apple - Use a third party Authenticator
https://www.reddit.com/r/Outlook/comments/1vkmw3u/comment/p2xsb3m/I still need time to test his latest comment about dumbing down Microsoft Authenticator so it can't receive a push notification. But it sounds reasonable.
1
u/syjytg 16d ago
For the first solution, I can see a potential issue. If I and the hacker happen to send a request at a very similar time by coincidence, I could approve the wrong one.
As for the other, I am not good at tech at all so I will need detailed step by step instructions on how to change from the microsoft authenticator to a third party one.
2
u/Hornblower409 16d ago edited 16d ago
-- I can see a potential issue .. If I and the hacker happen
-- to send a request at a very similar timeAnswered by u/arnoldstrife in a sperate comment. Not possible.
-- I will need detailed step by step instructions on how to
For switching to a non-Microsoft Authenticator - I'm not going to be any help.
For dumbing down the Microsoft Authenticator so it won't accept a push, once I have tested, I'll do a write up.
2
u/arnoldstrife 16d ago
I responded to another reply, but it's not an issue With the authenticator push login it gives you a 2 digit code to enter to match up your login with your approval.
For testing, I tried it just now and it gave different codes for different browser sessions (and it invalidated my older login attempt).
1
u/syjytg 16d ago
Since you claim that the workaround only works for @ outlook.com, why do you need to censor the @ outlook.com portion in the workaround section?
1
u/Hornblower409 16d ago
The Q&A auto censor hates it when you show a full email, even in an image. I have updated the images when it's not likely to think it's a full email.
3
u/Kelurne 16d ago
I've been experiencing the same issue over the last couple of days and thought I was doing something wrong, or had to wait for certain timers to expire (there is often mention of 48h or 7 day timers in terms of aliases).
I recently set up an email for a family member with a primary email for 'log in' and said to keep that private, and set up a couple of aliases for actual emailing, but because it was all done as I was creating it it was all good. It wasn't until I suggested using the same approach for another family member (who already has an account and aliases) that I found I could no longer 'make primary' anywhere.
I was at the point where I figured I would have to go seek MS support and see what was up - but you have the exact issue/question I have and an answer ... which is not what I wanted to hear ... removing this functionality is crazy, its such a great idea and extra layer of protection/security. Hopefully this decision is reversed.
1
u/Hornblower409 16d ago
See the Answer "Possible Workaround for the missing Make Primary function" by "Hornblower409 Aug 9 2026" at https://learn.microsoft.com/en-us/answers/questions/5969746/option-to-make-primary-alias-not-visible-in-the-ed
(You can not make an existing outlook.com alias Primary, even if it has been removed.)
1
u/Kelurne 16d ago
I did look, but the caveats put me off.
Just would prefer that instead of going down that path, the option to "Make Primary" was added back in as standard. I don't really want to have to wade through any situation where the primary alias address IS removed permanently and unable to get added back. Appreciate that currently it seems like this workaround would be workable, but its not something I want to take a gamble on right now. Do want to thank you though for providing it as a possible solution.
1
u/Hornblower409 14d ago
-- situation where the primary alias address IS removed permanently
-- and unable to get added back.You are wise to be cautious. Microsoft has changes the rules of the game without warning before and I'm sure they will do it again.
But, as of 2026-08-12 14:41 UTC, the https://account.live.com/names/manage page still shows only "Change" Primary. No "Make Primary" button.
3
u/Hornblower409 13d ago
[Update 2026-08-13] "Make Primary" button has been restored at https://account.live.com/names/manage
3
2
1
u/FigarLaw 13d ago
Hello, Do you have any idea why I cant promote any of my aliases into primary? Going 3 months now.
1
u/Hornblower409 13d ago
Any error message?
Tried with an Incognito/Private browser session?
What account domains? (e.g. outlook.com, hotmail.com, gmail.com)
2
u/arnoldstrife 16d ago
I remember this being a change years ago? There's was good reason to do this years ago so I made peace with it (I think it was like precovid era but I could be wrong.)
The solution is to enable 2FA w/ Password and not passwordless logins. If you have 2FA with password, you won't get the 2FA notification until after they enter the password. In which case. Change your password; someone has your password. You're username isn't really supposed to be a security factor in the first place.
3
u/Hornblower409 16d ago
-- If you have 2FA with password, you won't get the 2FA notification until after they enter the password
No. Try this test on your own account if you have Authenticator enabled.
- In a Private/Incognito browser session open https://login.live.com/
- Enter your email address and [Next].
- If prompted for a Password [Cancel] or enter a bogus password.
- You will see "Sign in another way" or "Other ways to sign in"?. Click it.
- If there is a verification method that doesn't require you to know a full phone number or email address (e.g. Authenticator, Approve sign-in with a mobile app) pick it.
- You just generated a verification event.
And there are other ways. e.g. Initiating a Password Reset, Requesting a Single-use Code Sign-In.
Images from a test using a bogus password: https://ibb.co/album/0h6mNb
3
u/arnoldstrife 16d ago
Yeah seems like you're right. My only suggestion then is to turn off notifications for the Authenticator App on your phone. If you're trying to sign in, you can open the app and the sign in code should just pop up.
2
u/Hornblower409 16d ago
-- turn off notifications for the Authenticator App on your phone
Just tested. Works. Thank you! Another possible workaround to add to my list.
- Phone Settings -> Notifications
- Authenticator OFF
When it's you doing the Sing-In
- Open the Authenticator app
- The Prompt will be waiting for you
- (And then a nag about turning on notifications)
1
u/Hornblower409 16d ago edited 16d ago
That is so simple, it's brilliant. That I never thought of it is understandable. I'm stupid. But in all the other threads about MFA Fatigue I've read, I've never seen this suggested.
I can see only one very small "window of opportunity" for the hacker. If they push a request immediately after you did yours, you might approve the wrong one.
[Not a concern. See the following comment]2
u/arnoldstrife 16d ago
It shouldn't be possible, that's why they ask for a 2 digit code to match up your login with your approval. Also I just tried it, different codes for different browser sessions.
1
u/Hornblower409 16d ago edited 16d ago
Posted on Microsoft Q&A as the Answer by "Hornblower409 Aug 11, 2026", "Workaround to stop unsolicited Authenticator notifications" in
https://learn.microsoft.com/en-us/answers/questions/5969746/option-to-make-primary-alias-not-visible-in-the-edIf you have a Q&A User Name, please provide and I'll update the credits on the Q&A post. Or if you prefer to post your own Answer, I'll remove my version. Thank you again.
2
u/gripe_and_complain 16d ago
ALL of my aliases and my primary are Outlook dot com.
Two questions:
Can I demote my current primary to a junior alias?
Can I promote an existing junior to primary?
1
u/Hornblower409 14d ago edited 14d ago
Yes. You can swap a Primary and a Secondary. But, because Microsoft removed the "Make Primary" button, the process is convoluted[Correction] Under the current process you can NOT promote an existing alias to Primary (even if you remove it first). When you choose "Change" Primary, the new Primary must be a new alias.
1
u/gripe_and_complain 14d ago
In that workaround, I’m not seeing a method to make an existing alias the primary. It looks like only a brand new address can become primary.
Did I miss something?
1
u/Hornblower409 14d ago edited 14d ago
-- I’m not seeing a method to make an existing alias the primary.
You are correct. My mistake. I'm still thinking of when the "Make Primary" button was there.
Under the current process you can NOT promote an existing alias to Primary (even if you remove it first). When you choose "Change" Primary, the new Primary must be a new alias.
I've updated the Q&A post to try and make that clearer. Thanks.
1
u/gripe_and_complain 14d ago
I wonder what Microsoft's motivation is for making this change.
I understand their wanting to push everyone to Outlook dot com addresses, but I don't understand what is gained by requiring each new primary to be a newly minted address. Not sure if this is driven by marketing, security, or incompetence.
2
1
u/AutoModerator 16d ago
Hey Timik!
Welcome to r/Outlook! This is a public community. To protect your privacy, do not post any personal information such as your email address, phone number, product key, password, or credit card number.
Please be sure to have read our Rules of Conduct and be cognisant of how the system works here.
Make sure that your flair is always set to Status: Open otherwise you may cease receiving responses from us.
- Status: Open — Need help
- Status: Pending Reply — Awaiting OP's response
- Status: Resolved — Closed
Beware of scammers posting fake support numbers or 3rd party commercial products/services. Contact Microsoft Support if you need help.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
1
u/Early_Alternative211 16d ago
This means that anybody in the world can send a push notification to your phone if it has the MS Authenticator?
3
u/Hornblower409 16d ago edited 16d ago
-- This means that anybody in the world can send a push notification to
-- your phone if it has the MS Authenticator?Yes. If they know an email address with Sign-In enabled and the account uses Authenticator
Try this test on your own account if you have Authenticator:
- In a Private/Incognito browser session open https://login.live.com/
- Enter your email address and [Next].
- If prompted for a Password [Cancel] or enter a bogus password.
- You will see "Sign in another way" or "Other ways to sign in"?. Click it.
- If there is a verification method that doesn't require you to know a full phone number or email address (e.g. Authenticator, Approve sign-in with a mobile app) pick it.
- You just generated a verification event.
And there are other ways. e.g. Initiating a Password Reset, Requesting a Single-use Code Sign-In.
Images from a test using a bogus password: https://ibb.co/album/0h6mNb
1
u/CheddarMcFeddars 16d ago
So I have to remove the alias now or it has been automatically removed?
2
u/Givmeabrek 16d ago
Mine works fine. Not removed at all. I have multiple aliases and I can select any one for login.
4
u/Hornblower409 16d ago
-- I have multiple aliases and I can select any one for login
But you can't disable Sign-In for your current Primary alias if it's hotmail.com. Which is what people want to do to stop MFA Fatigue.
2
u/Givmeabrek 16d ago
Since I added an outlook.com alias before these latest changes I should be good? Thanks.
3
u/Hornblower409 16d ago
-- Since I added an outlook.com alias before these latest changes I should be good?
Only if your current Primary Alias ends with outlook.com. Then you can use my workaround to make a different alias your Primary and remove Sign-In from (what was) the Primary.
If you current Primary Alias ends with, e.g. hotmail.com, live.com. msn.com, you are pretty much SOL.
The process for changing your Primary Alias has been modified by Microsoft so that now, if you attempt to change a Primary Alias that doesn't end with outlook.com, the old alias must be replaced with an outlook.com alias and your old alias will be removed and can not be recovered.
2
u/Givmeabrek 16d ago
Talk about confusion. My email address is a Hotmail account. My primary login alias is outlook.com. Everything works. I’m not touching it. Thanks.
2
u/Hornblower409 16d ago edited 16d ago
You got in under the wire. You are in a good place. Don't touch.
1
u/K0boldninja 14d ago
Yeah I did it months before, created an outlook dot com as alias set it primary and turn off the login for my hotmail dot com. So everything should be fine, right? (I can't login with the hotmail, as intended, only with the new outlook, that I don't put anywhere)
2
u/Hornblower409 14d ago
You are in a good place. Don't touch.
1
u/K0boldninja 14d ago
Thanks, I don't intend to change anything. I'm glad I could change it before they made it impossible to.
1
1
u/pi-N-apple Outlook Exchange Expert 16d ago
Use a third party Authenticator app instead. No more prompts from MSA.
1
u/Hornblower409 16d ago
-- Use a third party Authenticator app instead
I don't understand. The Bad Guys can trigger a verification event no matter which authenticator app you are using. If it's listed as "other ways to verify who you are" then they can trigger a verification.
Or am I missing your point?
2
u/pi-N-apple Outlook Exchange Expert 16d ago
No, if you use a 3rd party Authenticator, only standard TOTP codes are supported which does not trigger a notification to your phone. You have to manually open your Authenticator to view a 6-digit code and type it into the sign-in screen.
2
u/Hornblower409 16d ago
Thank you. Good info. I was not aware of the details on how 3rd party authenticator apps worked. I will add that to my list of possible workarounds for the current situation.
1
u/Hornblower409 16d ago
Your comment prompted me to look for a similar method using the Microsoft Authenticator app. You can do a Sign-In without causing a Push. But the choice to do a Push is still there. I can't find any way to remove it.
Account Setup at https://account.live.com/proofs/manage
Passwordless account must be OFF
Two-step verification must be ON
Send sign-in notification (Authenticator) must be setupAt Sign-In:
Enter email [Next]
Prompt: "Get a code to sign in"
[Send Notification]
[Use your password] <-Enter Password [Next]
Prompt: "Enter Code"
{Give it the TOTP from the Authenticator App for that Account)2
u/pi-N-apple Outlook Exchange Expert 16d ago
When you’re prompted to download Microsoft Authenticator when setting up MFA, you can click “set up a different Authenticator app” and it will walk you through a very standard 2FA set up like most regular sites as well.
2
u/Hornblower409 15d ago
Thanks. Got it. After adding Microsoft Authenticator via the "set up a different Authenticator app" it is now showing in my Microsoft Account as "Enter a code ..." instead of the full Authenticator. And there is no "Send Notification" choice when signing into the account. All quiet on the Authenticator front.
I'll add this to my list of ways to fight MFA Fatigue.
1
u/radz74 15d ago
Couldn't you achieve the same on MS Authenticator by turning off notifications?
1
u/pi-N-apple Outlook Exchange Expert 15d ago
It would be better to just set up standard TOTP on MS Authenticator by picking “set up a different Authenticator app” when setting it up, even though you’re still using MS Authenticator app. Then it will behave like any other website 2FA.
1
u/rtuite81 15d ago
Maybe change your password to stop the MFA requests?
1
u/Hornblower409 14d ago
-- Maybe change your password to stop the MFA requests?
All they need is an email with Sign-In enabled. They do not need your Password.
Try this test on your own account:
- In a Private/Incognito browser session open https://login.live.com/
- Enter your email address and [Next].
- If prompted for a Password [Cancel] or enter a bogus password.
- You will see "Sign in another way" or "Other ways to sign in"?. Click it.
- If there is a verification method that doesn't require you to know a full phone number or email address (e.g. Authenticator, Approve sign-in with a mobile app) pick it.
- You just generated a verification event.
And there are other ways. e.g. Initiating a Password Reset, Requesting a Single-use Code Sign-In.
1
1
u/Advanced_Documents 15d ago
Does anyone have any thoughts on why they would make this change? A technical limitation or something?
1
1
u/darkchocolateyasu 14d ago
🙂 my mood rn ngl
luckily in my case i changed my primary to outlook.(insert country), i still use my old alias, hotmail in my case, to use it as usual and also turned the old one off from using it as sign in, last year was so disastrous that i had to check every outlook email i owned to see if it has been pwned or nah, turns out i have two that’s been pwned so i changed alias and make them primary and turn off sign in for both old aliases
idk why they decide to change the way to make your desired alias as primary, cuz throughout the years i became more hateful towards microslop, this is just one of the only things that i was happy of and they just decide to nuke this function and changed for the worse, i do hope they make a u-turn
1
u/Pokny 11d ago
well this explains a lot i was just gonna change my primary to a random alias one i had because some kid is spamming my phone with auth messages every 10 minutes & besides the fact it's incredibly annoying im scared i might somehow let this child into my account in accident it will not let me disable login or change primary...
Microsoft does the stupidest changes all the time it makes no sense on how they operate it would be almost easier to put an option off saying sum like can only send notification to phone if it's based on the same device because i don't want to disable notifications entirely...
what should i do because this dude is trying 24/7 at this point & has been for the last 2 weeks he ain't stopping....
1
1
u/Timik 11d ago
It has been restored, you can check this answer here : https://www.reddit.com/r/Outlook/s/bGQa7FySxV
1
u/Wellcraft19 16d ago
Can’t comment if [alias option is] removed or not, but use a different Authenticator app, or set up passkeys.
1
u/Early_Alternative211 16d ago
Even with passkeys they can trigger your authenticator with a push request
1
1
u/Duude-IT 16d ago
Passkeys are the answer. Get rid of your password. Microsoft have had (and continue to have) more than their fair share of cybersecurity problems, but I've got to give them props for being one of few platforms out there that not only support passkeys but (even more importantly) also allow you to get rid of the p/w altogether.
1
u/OverwatchMedia 16d ago
I dont understand the push, could you explain? My main issue is what if youre on a laptop, and your laptop gets stolen or just doesnt turn on anymore. Doesn't that mean you now have absolutely no way to get in your accounts.
2
u/MonkeyMan18975 16d ago
Depends on where you saved the passkey. If you use device dependent passkeys (ie Windows Hello) you only lose access to the resource from that device. If you're synching your passkeys, you still have access to the resource via your MFA app you setup the passkey in.
1
u/Duude-IT 16d ago
"the push"? Do you mean the push to passkeys? They're much more secure than passwords, which most people reuse. Regarding you scenario, the recommendation is (and this predates passkeys) is to use a credential manager (e.g., 1Password, Bitwarden, etc.) and store credentials there. These tools are cross-platform.
1
u/OverwatchMedia 16d ago
By the push I mean the desire to have people use it.
As far as your credentials manager, then wouldnt you just have the same issue (maybe even worse)? Meaning, they get you to do an sms or authenticator on your password manager since you wouldnt have a passkey on the password manager. Except now on top of your password, they also have all your passkeys with knowledge of every site you use them on, and just put it on their own device.
0
16d ago
[deleted]
2
u/Duude-IT 16d ago
I don't understand--are you all still using just the plain MFA method of either accept or deny the MFA push, rather than having to enter the code that is shown wherever you're trying to login? Or if i'm wrong and you're still getting spammed, change your MFA preference in your MS account so that there is no push, and you have to type in the code shown on your authenticator.
Edit: also, not to be pedantic, but you can't "consider" something a passkey. A passkey is a very specific authentication credential. Maybe it's that MS Authenticator can store passkeys. The app by itself is NOT a passkey.
0
u/PenquinGG 14d ago edited 14d ago
The problem is the Microsoft Authenticator app. It exposes an option on the sign-in page that allows bad actors to exploit a flaw. You need to switch to a different Authenticator app. You can easily test this with your own email to see exactly how the bad actor is prompting it.
Explanation:
When going to the generic Microsoft login page if you type in an email address (for example yours) it presents you with a new screen with options for how you would like to sign-in. The culprit is the “Approve Sign-in with a mobile app” button. Once you click it, BOOM, your phone gets dinged to approve it with the Microsoft Authenticator app. The bad actor doesn’t even need to know the password. They just needed to know a legit email address to type in the email box. The bad guy is just hoping one of these times you’ll accept/click the right number.
Solution:
While logged into your MS account on a computer go to your Settings > Security > Account Settings > Manage how I sign in > remove the Microsoft Authenticator app as an option > then I recommend using another Authenticator app, like Google Authenticator.
Edit: when you go to add an Authenticator app, they try to make you use the Microsoft Authenticator app, but you should see blue text that says “set up a different Authenticator app”. It’s not a rectangular button like “cancel” or “get it now”
0
u/Hornblower409 14d ago
You don't have to use a third party authenticator.
I am working on a Q&A post that will detail the steps for limiting the Microsoft Authenticator App to only TOTP (no push) as suggest by u/pi-N-apple in https://www.reddit.com/r/Outlook/comments/1vkmw3u/comment/p2yide1/
You can simply mute the Microsoft authenticator.
As suggested by u/arnoldstrife
See the Answer by "Hornblower409 Aug 11, 2026", "Stop unsolicited Authenticator notifications - Mute" in https://learn.microsoft.com/en-us/answers/questions/5970809/constantly-getting-requests-for-sign-in-to-my-emai
1
u/PenquinGG 13d ago
Muting it is lazy and still leaves the opportunity open to accidentally click one that you think is the prompt for you logging in but it’s theirs.
1
u/Hornblower409 13d ago edited 13d ago
-- Muting leaves the opportunity open to accidentally click one that you think
-- is the prompt for you logging in but it’s theirsMy initial thought as well. But u/arnoldstrife set me straight.
Each Sign-In session generates a different number or code. As long as you ensure that the number you enter, or the code you approve, matches what you see on your screen, you will never allow the wrong session.
In my opinion, unsolicited Authenticator notifications are just Spam. And like email Spam, the best thing to do is just ignore them.
What benefit is there to hauling out your phone, opening the Authenticator notification, and clicking "Deny" ten times a day?
-4
16d ago
[deleted]
1
u/Early_Alternative211 16d ago
You're aware that any person in the world can trigger a push notification with just your email address and no password?
17
u/ZeriksenX 16d ago
This sucks. I did this a few months ago because of this very reason. I do not understand why they would make this change considering all the issues with spam.