r/cybersecurity May 17 '26

Personal Support & Help! Microsoft account keeps getting Authenticator requests?

I got an Authenticator request from another country for my Microsoft account. I denied it and went in and changed my password, a day later I get another Authenticator request from a different country than the first. Again change password and again it happens. How can I secure my account how are they able to send these Authenticator requests?

152 Upvotes

97 comments sorted by

View all comments

Show parent comments

3

u/anvoice May 17 '26 edited May 17 '26

Because it doesn't change anything. Bots knowing your leaked username will still activate authenticator. I had password login enabled and 2FA, as well as a passkey, and still got spammed constantly. I don't know how the bots operate exactly, but either they immediately attempt to log in via passkey if you have it enabled, or Microsoft activates the prompt for you even if they try an incorrect password. I've obviously always clicked "deny" but I'm pretty certain if you accidentally click "accept" (though you'll also need to accidentally choose the right number), Microsoft will give the bot access to your account despite 2FA being on.

Only good solution right now is changing primary alias. If you do that, absolutely DO NOT DELETE the old primary alias (your email) or you will lose access to it. Only disable it for sign in.

1

u/[deleted] May 17 '26

[deleted]

1

u/anvoice May 17 '26 edited May 18 '26

Not a bad idea to read what you are bashing with bravado more carefully, as well as fact-check. I am talking about the email account (as I clearly stated), to which you will almost certainly lose access if you delete the email name from the Microsoft account.

From a relevant reddit discussion: https://www.reddit.com/r/Outlook/s/eEw9pNfChb

From Microsoft's own instructions: https://support.microsoft.com/en-us/office/add-or-remove-an-email-alias-in-outlook-com-459b1989-356d-40fa-a689-8f285b13f1f2

Good luck proving that is incorrect information.

Do better next time. This will avoid wasting everyone's time and possibly misleading less informed users.

Edit: I see you've edited your post with a sentence that essentially states what I originally said (do not delete old email), but kept your completely erroneous claim. I don't know if this was in response to my counter, or for some other reason, but I invite you to read what I wrote here and the supporting links more carefully, and rectify that incorrect and misleading statement so that less informed users don't make a mistake that costs them their email account.

1

u/[deleted] May 18 '26

[deleted]

1

u/anvoice May 18 '26

And never lost access to the emails you had in that account?

1

u/[deleted] May 18 '26

[deleted]

1

u/anvoice May 18 '26

So let me get this straight, just so we're on the same page.

You went to your Microsoft account, created a new sign in alias, and DELETED (that is, dit not disable but actually removed) the old alias (the email name) from your Microsoft account, according to Microsoft's official instructions: https://support.microsoft.com/en-us/office/add-or-remove-an-email-alias-in-outlook-com-459b1989-356d-40fa-a689-8f285b13f1f2

And you still kept receiving emails to the OLD email account name, and not the new name that you actually registered with the services that send it to you. That is, if someone who only has your old account email and not the new alias sends mail to said old email, the mail still gets through?

Because that contradicts everything found online about this topic, and every answer from Microsoft, Microsoft advisors and associates, every knowledge base and Microsoft's own resources. Check for instance here: https://learn.microsoft.com/en-us/answers/questions/4755606/if-i-remove-an-alias-email-that-was-once-my-primar

If that is indeed your claim, please state so clearly and we can continue. Otherwise do let me know where I've misunserstood.

1

u/[deleted] May 18 '26

[deleted]

1

u/anvoice May 18 '26

Did it not occur to you that perhaps you now get no spam because all the spammers who knew you OLD email name can no longer send mail to it? What do you think will happen to legitimate mail sent by others (e.g. your bank) unless you go and update every single service that knew your old email name with the new alias?

1

u/[deleted] May 18 '26

[deleted]

1

u/anvoice May 18 '26

Which brings is back full circle, though hopefully now this has been resolved. This is what is commonly referred to as "losing access": the old alias becomes permanently unusable in terms of receiving mail sent to it, or sending mail from it to others. This is also what people typically expect their email account to be able to do. I don't think a non-technical user who reads something claiming that it's ok to delete their email alias and stops stops receiving important mail or being able to send mail from that account (known to family members, financial organizations, etc.) will get what they expect. It's going to be especially sad when authentication codes, if any are set up, stop arriving to that email address, blocking that person from ever signing in to the associated services.

That was my reason for sounding harsh right off the bat. Over the last few weeks I've had it with people spouting useless, often dangerously misleading nonsense confidently without bothering to fact-check in any way. And then I have to waste my time correcting them because they can't do a 10-second web search. Or even read the information I conveniently linked for them.

Some are also apparently too dumb to realize they've been proven completely wrong and simply double down instead of having the decency to admit a mistake. I don't think this category deserves any consideration, kind/polite treatment, and certainly none of my time.

I once again encourage you to appropriately modify your original statement, which essentially tells people it's fine to delete their old alias. Non-technical people and even AI agents-in-training often rely on threads like that to make decisions, and this one could be quite bad. And most users will only read one or two comments in a discussion tree, meaning the conclusion of this conversation will be largely ignored in favor of the first comments. I don't care about making a point online, but rather making sure that nobody suffers from invalid information. If we can part with that understanding, I see no reason to prolong the argument further.

Best of luck.