A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Unrequested Authenticator push notifications mean someone or something is repeatedly trying to sign in with that account. The protection is working as designed: as long as Deny is selected and the number is not approved, the attacker cannot get in.
To reduce risk and stop or limit these attempts, take these actions:
- Deny every unrequested prompt
- When a prompt appears that was not initiated, always select Deny. This keeps the account safe even if someone has the password.
- If the prompt is coming from Outlook mobile or a similar companion app, this behavior is the same: unrequested prompts should always be denied.
- Secure the account in Microsoft account security
- Sign in to the Security basics page for the Microsoft account.
- Select Review activity and check the Recent activity page for unfamiliar sign-in attempts.
- For any activity that is not recognized, expand it and choose This wasn't me or Secure your account as described in the guidance. This helps block suspicious sign-ins and may force attackers to re‑prove access.
- Change the password from the Security basics page to a strong, unique password that is not reused anywhere else.
- Keep number matching and MFA enabled
- Number matching in Microsoft Authenticator push notifications is a security feature that prevents attackers from approving prompts blindly. It cannot be turned off for push notifications and should remain enabled because it significantly reduces the chance of accidental approval.
- Ignore delayed or accidental prompts
- Some prompts may be delayed or triggered because someone mistyped an email/phone or because a previous request was delayed in delivery. Regardless of cause, any prompt not initiated should be denied.
If there is a belief that someone has already accessed the account, follow the full guidance for unusual sign-ins and compromised accounts from the Microsoft account security pages, including reviewing recent activity and updating all security info.
References: