Why can others send MFA prompts without first entering a password? (Personal M365 accounts only)

Nick Hawkins 20 Reputation points
2026-01-08T19:55:25.2766667+00:00

I've been getting bombarded by these stray requests for the past few days. Easily 2-3 times an hour from different countries.

In my testing with different devices, fresh browsers, and different networks / VPNs, I've found that you only need to enter a valid email address tied to a personal M365 account (not "work or school").

Once I entered the email, I automatically get a "sign in another way" screen where I can hit "approve sign in with a mobile app" to send a prompt without entering a password first.

On mobile, it's even worse! After entering a valid email, I get taken directly to a "get a code to sign in" page with a huge "Send notification" button.

Hopefully no one can get in unless I happen to accidentally tap the correct number (33% chance) instead of hitting "deny".

My understanding of "Two Factor Authentication" was that someone would need to pass through the "First factor" (password) before the "Second factor" can be triggered. I truly hope something is broken and that this isn't a "feature".

====================

Under my account "security settings", I can see "send sign in notification" listed as as "sign-in option".

If I go to remove this, it says my authenticator will be unlinked. Changing my PW has no effect either since they don't need to enter one..

I would really like my authenticator to be "2FA Only" instead of "2FA and initial sign in method"

Microsoft Security | Microsoft Authenticator

1 answer

Sort by: Most helpful
  1. AI answer

    2026-01-08T19:55:35.77+00:00

    In the case of personal Microsoft 365 accounts, the behavior you're experiencing with multifactor authentication (MFA) prompts can occur due to the way the authentication process is designed. When you enter a valid email address associated with a personal account, the system allows for alternative sign-in methods, including sending a notification to the Microsoft Authenticator app without requiring the initial password entry. This is part of the streamlined sign-in experience aimed at enhancing user convenience.

    However, this can lead to situations where users receive multiple unwanted sign-in requests, as you described. It's important to note that while the system allows sending notifications without a password, the actual access to the account still requires the user to approve the sign-in request through the Authenticator app. If the request is not approved, no access is granted.

    If you prefer a more traditional two-factor authentication setup, where a password is required before any MFA prompts, you may need to adjust your security settings or consider unlinking the Authenticator app as you mentioned. However, unlinking it may affect your ability to use it for MFA altogether.

    For further assistance, you might want to reach out to Microsoft support or check the security settings in your account to explore options that align with your preferences for MFA.

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.