Authenticator is spamming with sign-in requests.

Håkan Arnoldson 0 Reputation points
2026-05-09T14:57:44.8933333+00:00

The authenticator app seems poorly designed in that anyone can create sign-in requests that wakes me up in the middle of the night by a notification on my phone without even entering my password first.

I just removed it and choosed Google Authenticator as the app sign-in option instead to solve this.

But you need to look into this it should not be possible to create a notification sign-in request without having authorized in another step first and just spam everyones phones by just having the email...

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-05-09T14:58:01.1833333+00:00

    Microsoft Authenticator notifications are generated as part of multifactor authentication (MFA) and passwordless sign-in flows, and they are intended to be an extra factor after a primary sign-in step such as entering a username. The app supports:

    • Passwordless sign-in via notifications, where after entering a username the user is prompted in Authenticator to approve the sign-in by selecting a number.
    • MFA via notifications, where a push notification is sent and the user must select Verify or Deny.

    If unexpected notifications appear (for example, at night), they typically indicate someone is attempting to sign in using the account identifier (email address). In those cases, the correct action is to deny the request and, if possible, change the account password and review security settings.

    To reduce disruption from notifications while still using Authenticator:

    1. Use verification codes instead of push notifications
      • Authenticator can be used as a software token to generate OATH verification codes. After entering username and password, the user enters the code from the app. This avoids unsolicited push prompts because no notification is sent; the user must actively open the app and read the code.
    2. Use passkeys or passwordless sign-in with strong device factors
      • Authenticator supports passkey sign-in, where the user completes phishing-resistant authentication with biometric or device PIN. This keeps the strong factor on the device and reduces reliance on push prompts.
    3. Ensure anomalous sign-ins don’t generate unnecessary notifications
      • Starting August 2023, anomalous sign-ins and sign-ins from unfamiliar locations do not generate notifications automatically. To approve such sign-ins, the user must open Authenticator (or Authenticator Lite in a companion app like Outlook) and manually refresh to see and approve the request. This change reduces unsolicited prompts.
    4. If notifications are still disruptive
      • Notifications can be disabled at the device level (for example, via Do Not Disturb or per-app notification settings), and Authenticator can be used only for verification codes instead of push approvals.

    If Authenticator is removed or replaced with another app, ensure at least one secure MFA method remains configured (such as another authenticator app with TOTP codes) so that account access is not lost.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.