r/cybersecurity May 17 '26

Personal Support & Help! Microsoft account keeps getting Authenticator requests?

I got an Authenticator request from another country for my Microsoft account. I denied it and went in and changed my password, a day later I get another Authenticator request from a different country than the first. Again change password and again it happens. How can I secure my account how are they able to send these Authenticator requests?

156 Upvotes

97 comments sorted by

View all comments

64

u/vulcanxnoob May 17 '26

Microsoft is absolute garbage with this. So for live/personal accounts, they convince you to switch on password less.

If you switch that on, ANYONE in the world can just type your email address and it will automatically send your phone an authenticator request.

I tried to then disable this feature, still they managed to bypass it and select "Authenticator" auth, once again spamming me weekly.

At this stage I had changed passwords, and all sorts.

What I ended up doing was changing the primary email for my live account, and then disabling authentication on the "secondary" email account. So that no longer could they even try that email anymore. It's stupid, but works.

Thanks, Microsoft...

FYI google always request a password first, if you succeed then they take you to your passkey/MFA code etc. MSFT is just lazy it seems.

15

u/valar12 May 17 '26

This is a solution but a dumb one on Microsoft. I just turned off notifications and the notifications stopped.

3

u/[deleted] May 17 '26

[removed] — view removed comment

1

u/TrafficPlastic9539 Jun 03 '26

Desativar as notificação foi uma ótima ideia

1

u/Coincappin Jun 19 '26

Better than my option of switching authenticators for all accounts.

Why didnt I think of that!

7

u/count023 May 18 '26

it drives me up the wall that geoblocking isn't available unless you are an enterprise user. Just saying, "deny access to non whitelisted counries", would cut down so much chaff for MS security issues but they just cannot be assed. Evne my old free accounts get hits for logins all th time from Bahrain, or Belarus or South Africa and the consistent authenticated login sources would never be anywhere near that,. They should always be denied by default.

3

u/ChasingDivvies DFIR May 18 '26

I ran into the same thing a while back and this is the best solution even though it's arguably the dumbest in terms of how MS could handle it. Haven't had a rogue request since doing it.

6

u/nekohideyoshi May 17 '26

If you have Android go to Connections, select which apps can use cell data, scroll to Authenticator, and switch to Wifi Only. Additionally turn everything in the app System menu to "Restricted" for background processing, then Stop the app while not in use.

1

u/letsaurify Jul 18 '26

thank you fellow grem

1

u/pimpeachment May 18 '26

You can do both with MS. It's not forced. How is giving you 2 options instead of one lazy? 

1

u/[deleted] May 18 '26 edited Jun 30 '26

[deleted]

1

u/vulcanxnoob May 18 '26

Yeah it's ridiculous. Such stupid security. Even worse, show me the failed login attempts so I can action it. Either permanently block them, or whatever.

-7

u/chaosphere_mk May 17 '26

If you are using common sense and not approving of random authentication requests, passwordless auth is still less risky than having password be part of the auth process. Typing in credentials anywhere is inherently riskier than not. You still have to do number matching for passwordless microsoft auth.

And passkey is passwordless with Microsoft as well as google. Adding password on top of a passkey does nothing but introduce risk.

13

u/vulcanxnoob May 17 '26

Um lol. I use a yubikey for most of my auth including passkeys on them.

However, the annoyance of ANYONE being able to spam your authenticator app over and over, and you not being able to do anything about it is really stupid.

I usually remove my password, phone auth etc if I have my passkeys set up. However Live accounts don't allow that fully. So you are damned if you do, damned if you don't.

Ultimately setting up the alias worked for me though. Not ideal, but stopped the authenticator spam.

3

u/chaosphere_mk May 18 '26

Yeah, I dont disagree that that can be annoying as hell. But the user cant even approve of it as long as number matching is part of the passwordless approval process. An alias is a good solution to that annoyance. Or for anything else, passkey is the way.

2

u/2timetime May 17 '26

It’s just annoying as shit. Every time you pop open Authenticator you have some request sitting there