Share via

Countless externally triggered authentication requests

CMH 20 Reputation points
2026-06-01T05:08:29.93+00:00

Dear Microsoft Team, I have been using the MS Authenticator app for years now—and I do own several OS licenses—but for the past few weeks, I have been receiving authentication requests on my app from all over the world. I have already changed my password, yet these requests simply will not stop. When are you going to close this data leak? When will there be a patch for the app that finally puts a stop to this?

Microsoft Security | Microsoft Authenticator
0 comments No comments

Answer accepted by question author

AI answer

2026-06-01T05:08:46.5+00:00

The repeated, unsolicited prompts in Microsoft Authenticator are not caused by a data leak in the app. They are typically the result of someone repeatedly trying to sign in to the account using the correct username but guessing or reusing a password. Because the account is protected with multi-factor authentication, those sign-in attempts generate “Are you trying to sign in?” prompts.

According to the guidance, if an unrequested prompt appears, it may be because:

  1. Someone is trying to access the account.
  2. Someone accidentally entered the wrong phone/email when trying to sign in.
  3. A previously requested prompt was delayed in delivery.

Any request that was not initiated must be denied. Without the correct response in Authenticator, attackers cannot complete the sign-in and the account remains protected.

To reduce risk further:

  • Continue to deny all prompts that were not initiated.
  • Ensure the account uses a strong, unique password and multi-factor authentication.
  • Review account security and recent activity to confirm there is no successful unauthorized access.

There is no indication in the provided material of a known “data leak” in Microsoft Authenticator or a pending patch specifically to stop such prompts; the prompts are a security control indicating blocked sign-in attempts, not a defect in the app.


References:

AI-generated content may be incorrect. Read our transparency notes for more information.

Was this answer helpful?

1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. CMH 20 Reputation points
    2026-06-01T06:30:39.78+00:00

    How is it possible that I am still receiving requests, even though I changed my password—to one with over 24 characters—several days ago? I even changed the password for the email account under which I am registered. Is it possible for me to change my email address as well? Or could that lead to issues with the operating systems?

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.