A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Those repeated number‑matching prompts mean someone is repeatedly trying to sign in as that account and triggering Microsoft Authenticator notifications. The notifications themselves are a protection mechanism; they cannot be selectively disabled without also changing how sign‑in works.
To reduce or stop the OTP/push prompts, use these approaches:
- Deny every unexpected prompt
- When a notification appears that was not initiated, always choose Deny. This prevents unauthorized access.
- Switch to verification codes instead of push notifications (where possible)
- In the sign‑in security settings for the account, change the default method from “Notification through mobile app” to “Use verification code from mobile app” (time‑based codes).
- With this setup, the Authenticator app generates codes locally and does not send push notifications for sign‑ins; the code is entered manually when needed.
- Use alternative methods if available
- If the account supports other passwordless or MFA methods (for example, SMS, email codes, or security keys), configure one of those as the primary method and reduce reliance on push notifications.
- Keep device and app secure
- Ensure the device clock is set automatically and correctly so that codes and notifications work reliably.
- Keep Microsoft Authenticator installed only on devices that are actively used and remove it from old devices to avoid confusion about where prompts appear.
If the prompts continue at a high rate even after changing methods, it indicates ongoing attack attempts. In that case, review and tighten account security (change any associated passwords, review recovery methods, and consider additional protections such as conditional access if this is a work/school account).
References: