A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Yes. Two-step verification (2FA) is applied at the Microsoft account level, not separately per service.
- When someone tries to sign in to OneDrive in a browser using that Outlook/Microsoft account, the same two-step verification protection applies. They must pass both the password and the second factor (code, Authenticator approval, etc.) before accessing OneDrive.
- The same applies when signing in to OneDrive in Windows (for example, the OneDrive sync client tied to that Microsoft account). If the account has two-step verification enabled, the sign-in flow will require the second factor when first adding the account or when security conditions require re-authentication.
For additional protection of specific sensitive files, Personal Vault in OneDrive adds its own extra authentication step on top of the account’s 2FA.
References: