A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Microsoft Authenticator notifications are generated as part of multifactor authentication (MFA) and passwordless sign-in flows, and they are intended to be an extra factor after a primary sign-in step such as entering a username. The app supports:
- Passwordless sign-in via notifications, where after entering a username the user is prompted in Authenticator to approve the sign-in by selecting a number.
- MFA via notifications, where a push notification is sent and the user must select Verify or Deny.
If unexpected notifications appear (for example, at night), they typically indicate someone is attempting to sign in using the account identifier (email address). In those cases, the correct action is to deny the request and, if possible, change the account password and review security settings.
To reduce disruption from notifications while still using Authenticator:
- Use verification codes instead of push notifications
- Authenticator can be used as a software token to generate OATH verification codes. After entering username and password, the user enters the code from the app. This avoids unsolicited push prompts because no notification is sent; the user must actively open the app and read the code.
- Use passkeys or passwordless sign-in with strong device factors
- Authenticator supports passkey sign-in, where the user completes phishing-resistant authentication with biometric or device PIN. This keeps the strong factor on the device and reduces reliance on push prompts.
- Ensure anomalous sign-ins don’t generate unnecessary notifications
- Starting August 2023, anomalous sign-ins and sign-ins from unfamiliar locations do not generate notifications automatically. To approve such sign-ins, the user must open Authenticator (or Authenticator Lite in a companion app like Outlook) and manually refresh to see and approve the request. This change reduces unsolicited prompts.
- If notifications are still disruptive
- Notifications can be disabled at the device level (for example, via Do Not Disturb or per-app notification settings), and Authenticator can be used only for verification codes instead of push approvals.
If Authenticator is removed or replaced with another app, ensure at least one secure MFA method remains configured (such as another authenticator app with TOTP codes) so that account access is not lost.
References: