A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Microsoft uses SMS (text messages) and certain short codes (like 69525) to send verification codes and security alerts, and may also send security notifications by email. The documented, genuine messages:
- Come from short code 69525 or the sender name “Microsoft” for SMS.
- May include links that start with aka.ms.
- Are used when signing in, using features that require identity verification, or when unusual sign-in activity is detected.
There is no documentation indicating that Microsoft sends authentication/verification codes over WhatsApp. Official guidance is:
- Treat unexpected or unusual verification messages as potentially suspicious, especially if they arrive via a channel that is not documented (such as WhatsApp).
- If a verification code or sign-in prompt is received that was not explicitly requested, do not respond or use it. Instead, secure the account.
To help protect the account after receiving an unexpected or non-standard verification message:
- Go directly (by typing the address, not using any link in messages) to https://account.microsoft.com or https://account.live.com and sign in.
- Review recent sign-in activity on the Recent activity page and mark any unfamiliar activity as “This wasn’t me.”
- Change the account password to a strong, unique one.
- Review and update security info (phone numbers, alternate email addresses, and sign-in methods) on the Security basics page.
- Consider enabling or tightening two-step verification or going passwordless using documented methods such as Microsoft Authenticator, SMS, email codes, Windows Hello, or security keys.
If verification codes are ever received that were not requested, do not use them; the account remains safe as long as the attacker does not get the code. In that case, follow the “unrequested verification codes” guidance and strengthen sign-in methods.
References: