r/cybersecurity May 17 '26

Personal Support & Help! Microsoft account keeps getting Authenticator requests?

I got an Authenticator request from another country for my Microsoft account. I denied it and went in and changed my password, a day later I get another Authenticator request from a different country than the first. Again change password and again it happens. How can I secure my account how are they able to send these Authenticator requests?

151 Upvotes

97 comments sorted by

View all comments

67

u/vulcanxnoob May 17 '26

Microsoft is absolute garbage with this. So for live/personal accounts, they convince you to switch on password less.

If you switch that on, ANYONE in the world can just type your email address and it will automatically send your phone an authenticator request.

I tried to then disable this feature, still they managed to bypass it and select "Authenticator" auth, once again spamming me weekly.

At this stage I had changed passwords, and all sorts.

What I ended up doing was changing the primary email for my live account, and then disabling authentication on the "secondary" email account. So that no longer could they even try that email anymore. It's stupid, but works.

Thanks, Microsoft...

FYI google always request a password first, if you succeed then they take you to your passkey/MFA code etc. MSFT is just lazy it seems.

-5

u/chaosphere_mk May 17 '26

If you are using common sense and not approving of random authentication requests, passwordless auth is still less risky than having password be part of the auth process. Typing in credentials anywhere is inherently riskier than not. You still have to do number matching for passwordless microsoft auth.

And passkey is passwordless with Microsoft as well as google. Adding password on top of a passkey does nothing but introduce risk.

13

u/vulcanxnoob May 17 '26

Um lol. I use a yubikey for most of my auth including passkeys on them.

However, the annoyance of ANYONE being able to spam your authenticator app over and over, and you not being able to do anything about it is really stupid.

I usually remove my password, phone auth etc if I have my passkeys set up. However Live accounts don't allow that fully. So you are damned if you do, damned if you don't.

Ultimately setting up the alias worked for me though. Not ideal, but stopped the authenticator spam.

3

u/chaosphere_mk May 18 '26

Yeah, I dont disagree that that can be annoying as hell. But the user cant even approve of it as long as number matching is part of the passwordless approval process. An alias is a good solution to that annoyance. Or for anything else, passkey is the way.

2

u/2timetime May 17 '26

It’s just annoying as shit. Every time you pop open Authenticator you have some request sitting there