A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Unrequested Microsoft Authenticator (or Outlook/Authenticator Lite) prompts usually mean one of the following:
- Someone is trying to sign in to the account using the correct username but without the second factor.
- Someone accidentally typed the email address or phone number when trying to sign in to their own account.
- A sign-in prompt that was legitimately requested earlier was delayed and arrived later than expected.
In all of these cases, the account remains protected as long as the request is denied and no code/number is approved.
To handle and prevent this:
- Always select Deny/Refuser for any sign‑in prompt that was not initiated.
- Review the account’s recent activity to confirm whether there are unfamiliar sign‑in attempts and, if so, follow the guidance there to secure the account (change password, review security info, etc.).
- Consider strengthening security by using passwordless methods (for example, Microsoft Authenticator notifications, Windows Hello, security keys) instead of passwords alone, as these are harder to guess or phish.
- If unwanted prompts continue, temporarily disable that sign‑in method (for example, Outlook mobile sign‑in requests) in the account’s security or app settings and re‑enable it later if needed.
As long as unrequested prompts are denied and security information is kept up to date, these attempts cannot complete a sign‑in.
References: