I keep getting emails for a single-use code.

Anonymous
2023-08-07T16:14:20+00:00

Hi,

I keep getting emails for a single use code in my email. I probably receive 10 emails a day for the past few weeks. And I haven't been trying to request a code.

Email says:

We received your request for a single-use code to use with your Microsoft account.

Your single-use code is: 4*****7

If you didn't request this code, you can safely ignore this email. Someone else might have typed your email address by mistake.

Thanks,

The Microsoft account team

It's quite annoying. The email sender is from ___@___.___

I would like to stop getting these emails as I'm not trying request a code.

Outlook | Web | Outlook.com | Account management, security, and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2023-08-07T16:45:37+00:00

Hello Priscilla_A,

Welcome to the Microsoft community.

I'm a Microsoft user like you, I hope you're doing well?

I understand how discomforting it can be to receive a one-time security code for your account when you didn't initiate.

However, it's a good idea to ignore this code if you haven't requested it.

One-time code is an essential security feature that prevents unauthorized access to your account. One-time code is required to access your account. These codes can be used only once and has expiration time for their usage.

You may receive one-time code emails if:

  1. Signing into your Microsoft account from a new device or browser.
  2. Resetting your Microsoft account password.
  3. Making changes to your Microsoft account security information.
  4. Signing into your Microsoft account from a new location.
  5. Unusual and suspicious activity is detected on your Microsoft account.

If someone mistakenly enters your account email ID, you can't stop them, that's out of your control (you don't know who it is), All you can do is ignore it, as suggested in the email.

The same applies if someone may be trying to intentionally access your Microsoft account, a one-time code is a security feature that prevents this unauthorised access.

You don't control the actions of others, hence you can't stop it.

If there was a way to stop it, Microsoft would state it in an email rather than suggesting you to ignore it any one-time code you did not initiate.

I will suggest you check your Microsoft account sign-in activity to make sure there are no unauthorised access. You can see a list of devices and browsers that have accessed your account recently.

Microsoft account management website: https://account.live.com/Activity

Here are a few things you can do to make your Microsoft account more secured:

  1. Create a strong password for your account
  2. Use the Microsoft Authenticator phone app to sign in without a password
  3. Make your account easier to recover
  4. Make sure your operating system has the latest updates
  5. Never reply to email asking for your password
  6. Check your recent activity
  7. Keep your devices safe

Click link below for more information:

https://support.microsoft.com/help/628538c2-7006-33bb-5ef4-c917657362b9

If you are receiving blackmail emails, please report this issue to the nearest authorities.

Please let me know if you need any further assistance.

Give back to the community, help the next person who has this problem by pointing out if this answer solved your problem. Click "Yes" or "No" below.

Warm Regards

Was this answer helpful?

500+ people found this answer helpful.
0 comments No comments

137 additional answers

Sort by: Most helpful
  1. Anonymous
    2024-05-04T18:45:42+00:00

    I experimented. I turned on 2FA (two-factor authentication). With 2FA enabled, I cannot log in to the account with a single six-digit code. I need either my password plus a six-digit code, or two six-digit codes from separate sources. (A source is an email account, a physical security key, or an authenticator app. I don't think SMS is allowed in this case, but I did not check carefully.)

    I'd say the biggest problem is that MSFT makes it so hard to turn on 2FA. By contrast, IIRC my bank simply forced me into using 2FA.

    This appears to leave my phone as the weakest link. Someone able to log in to my phone would be able to use the authenticator app and see both email accounts that I have registered on MSFT. I do lock my phone with a PIN, so the phone weakness involves stealing my phone and guessing the PIN before the phone disables itself.

    This probably will not stop the emails, but will eliminate the opportunity for the cracker to get in by guessing the six-digit code. I could stop the emails by removing the addresses from my MSFT account and depending on the authenticator app. If the emails start to bother me, I can filter them straight to the trash, where I could retrieve them if I ever actually needed them. (By using password and authenticator app, I should never need the emailed code.)

    So my advice is: turn on 2FA on your MSFT account. If you use a banking app, you are probably familiar with the 2FA concept already.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2024-05-02T21:08:33+00:00

    That's exactly it, I've stopped using a password, I now have to use my phone authentication. It shouldn't even be letting people use a one time password or code. It's ridiculous, you're right six numbers much easier to fluke guess when they log in hundreds of times.

    Was this answer helpful?

    0 comments No comments
  3. Ron-6928 4,991 Reputation points
    2024-05-02T20:46:30+00:00

    I didn't read your entire post. Just want to point out the real problem is bypassing user password, at least in my case. My complex password becomes useless if sign in procedure doesn't even ask for it. They replace it with an easier to guess 6 digit code. Anyone who knows my email address can be a lucky hacker.

    So your advice means absolutely nothing: "be very certain that your password is very secure". Your 25+ character alphanumeric + symbols won't be needed. Hackers only need the 6 digit code to break in.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2024-05-02T16:47:58+00:00

    It would certainly help if MSFT improved the wording of the message. Instead of "Someone else might have typed your email address by mistake", it should say "Someone is trying to break into your account". Of course they won't do this, because users would panic (and would be justified in doing so), and try to call MSFT for help (which MSFT doesn't want to happen). They are not totally averse to accurate wording -- I just added an authenticator login method and received an email stating "If this wasn't you, a malicious user has access to your account".

    The real problem is that authentication codes are only six digits. If the attacker attempts to crack one account per second and simply guesses a six-digit number, on average they will crack an account every eleven days. And surely they can make far faster attempts using botnets -- cracking several accounts per day is not out of reach. Authentication codes should be expanded to at least twelve digits. Unfortunately, even authentication apps and devices generally use six-digit codes, or eight digits at most.

    Since I have added an authenticator app, I should be able to remove the other methods of receiving a code. Currently I'm only receiving codes at one email, but I suspect that if I remove that method, I'll start getting that at another email or a text. I think I'll have to remove all three and leave just the authenticator app.

    But that still leaves the danger from the six-digit codes. If the attacker is hitting my account ten times a day -- a rate that some people have seen, though mine is less -- it would be about 300 years ON AVERAGE before my account is compromised. I might be able to live with that -- me and the internet will change a bit in that time -- but that comes out to several hundred people in my city being compromised annually.

    So I may eventually remove all recovery methods. This of course requires being absolutely certain that I can always find my password. I've worked in Information Technology for over 50 years, and even I have to think hard before saying I'm totally certain. I'm certain but I don't want to count on it in a hurry ...

    Stanivuk Bujas wrote: "it's plainly obvious that someone is using a VPN while trying to brute force the single-use code. IP address that has made the unsuccessful login attempt changes from country to country". Actually, I think what this says is that someone is using botnets for the attack. Most email providers are by now mostly successful in blocking traffic from known botnet nodes, including surely Outlook. So MSFT should be blocking login attempts from known botnet nodes. Maybe they are and this is just the remnants that haven't been cataloged yet. Or maybe as part of their push to have all Windows users sign in to microsoft.com just to use their own Windows computer, they are forced to accept connections from botnets.

    "IP address is never from MY country, so I am clearly not targeted in any intelligent way.. it's just brute force and scripts". I agree, and this is important. Attempt a login, and after entering a password that's expected to fail, ask for a code. A few seconds later, enter a random six-digit number. This will only succeed one time in a million (annoying a million users in the process), but that's enough for a script kiddie with a botnet. What I do not know is whether guessing the code is sufficient to crack the account if two-factor authentication (2FA) is set -- perhaps account recovery requires access to two methods -- say two email accounts, or SMS plus authenticator code, etc.

    "I understand the low probability of attackers guessing a 6-digit number". Yep, but one in a million ...

    So in closing: I think (not yet verified) the way to stop these cracking attempts is to remove all account recovery methods from one's MSFT account, other than authenticator apps. Of course, before doing this, be very certain that your password is very secure (see https://lowe.github.io/tryzxcvbn/) and that you can always figure out where you saved it. Use a password manager, and print a copy of the password manager's login info and put it in a safe deposit box. Or something like that.

    Was this answer helpful?

    0 comments No comments