Error Code: 399287 MFA via SMS not working - BadReputation

2026-06-15T06:05:58.2633333+00:00

We are experiencing an issue with MFA via SMS in our tenant and have been for the past few months or so. When attempting to use SMS for MFA, the authentication fails with the following error:

{"Success":false,"ResultValue":"BadReputation","Message":"BadReputation","AuthMethodId":"OneWaySMS","ErrCode":399287,"Retry":false,"FlowToken":"Removed","SessionId":"","CorrelationId":"<pii removed>","Timestamp":"2026-06-09T12:45:13Z","Entropy":0,"ReselectUIOption":0,"ContinuationToken":null,"MobileAppAuthDetails":null}

Request: Unblock the tenant from the Azure Phone Fraud Protection system, making us able to use SMS MFA again.

I'm able to provide email address, phone number, tenant id, country and country code if requested via a private message. We are unable to contact the Data Protection team, as when we get through the AI assiatants, the phone is hung up from their side for some reason.

Thank you in advance.

Best regards,

Kristian

Microsoft Security | Microsoft Entra | Microsoft Entra ID

Answer accepted by question author
Shubham Sharma 17,930 Reputation points Microsoft External Staff Moderator
2026-06-15T06:41:59.07+00:00

Kristian Bentsen Kjærgård (KBK)

Thank you for sharing your details via private message.

I’ve reached out to the engineering team regarding the MFA issue on your account. They have now unblocked it from the backend and cleared the bad reputation associated with it. You should be able to log in to the Azure Portal without any issues.

Please try signing in and verify if you can complete SMS authentication successfully. Let me know if you encounter any problems.

As a best practice, I recommend registering the Microsoft Authenticator method for your account instead of relying on SMS. SMS and voice call authentication methods are more vulnerable to IRSF attacks (telephony fraud) and are generally less secure.

For better practice, I recommend registering with Microsoft Authenticator method to your account instead of SMS method as these SMS/Voice telecom auth methods are susceptible to IRSF attacks telephony fraud.

If the resolution was helpful, please take a moment to accept the answer and upvote it 👍 to make it helpful to the community.

Thank you for contacting Microsoft Q&A!

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

0 additional answers

Sort by: Newest

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.