Microsoft Authenticator
A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation.
6,064 questions
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
I currently have the Microsoft Authentication app setup which contains all my TOTP's. I noticed that on the Microsoft Authentication app, I have two different TOTP's for the same microsoft account(One is a 6 digit TOTP as usual, and the other is a 8 digit TOTP). Both of them seem to work in the 2FA field during sign-in. I believe this is a security vulnerability as now I have 2x 2FA which works. I tried disabling removing/disabling the 2FA and then re-added them. I received a new secret(QR code), which works, but the 8 digit TOTP is still there and it also works....