A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Select no response in Microsoft Authenticator and let the request time out. Any prompt that was not initiated should simply be ignored.
For unrequested prompts:
- Do not enter the code or tap Approve.
- Let the notification expire; this is effectively denying the attempt.
- Treat it as a possible attack and secure the account.
To secure the account after seeing an unrequested prompt:
- Sign in to the account only when ready to do so, and only from a trusted device and network.
- When signing in, the Authenticator prompt or code that appears immediately after entering the username and password is the one tied to that specific sign-in attempt. Use it only if the timing matches the sign-in just performed.
- After successfully signing in, change the account password and review security info (phone, email, sign-in methods) to remove anything not recognized.
- Consider enabling or keeping passwordless sign-in (for example, using Microsoft Authenticator, Windows Hello, or security keys) to reduce risk from password guessing or phishing.
If unrequested codes or prompts continue, do not respond to them. Without the correct code or approval, attackers cannot complete sign-in.
References: