Catch-22: iOS MS Authenticator Prompt Blocks the Number Matching Codes

nya 15 Reputation points
2023-02-22T20:25:18.1533333+00:00

We've started piloting a small group at our organization with number matching MFA, as Microsoft will enforce number matching in May 2023. We are NOT using conditional access, but are currently on per-user MFA.

Some iOS users have reported issues when they need to reauthenticate the Outlook app on their iPhones with Microsoft Authenticator installed. They are redirected from Outlook to Microsoft Authenticator to enter a password, and before the user is presented with a two-digit code, the notification prompts show up, completely covering the two-digit code needed for number matching.

User-submitted image - The two-digit code is hidden behind the prompt.

Microsoft Authenticator blocking the number matching number

There is no option to temporarily hide the notification prompt or peek behind the notification. Maybe the app/geolocation displayed is causing the issue, but we would like to keep them displayed. You will be able to see the two-digit code once you select 'No, it's not me', but obviously the code is now invalid, and generating a new two-digit code will push new notification prompt to block the newly generated number.

The current workaround is to select "No it's not me", then hit "Get Codes", copy one-time passcode, "I can't use my Microsoft Authenticator app right now", then select OTP, then paste the code, but the workaround is not practical for average users. Good thing Outlook for iOS is logged in persistently but we expect to get more calls with the upcoming number matching deadline in May.

Has anyone experienced a number matching issue on Microsoft Authenticator with iOS? Just wait for MS to update the app?

Microsoft Security | Microsoft Entra | Microsoft Entra ID
Microsoft Security | Microsoft Authenticator
{count} votes

6 answers

Sort by: Most helpful
  1. nya 15 Reputation points
    2023-03-20T23:57:20.35+00:00

    We eventually discovered the "I can't see the number" option after a few user reports (you need to scroll down the dialog when text scaling is modified). Issues were all reported by users who adjusted text scaling in iPhone's Accessibility Options.

    The bigger problem is, whoever adjusting iPhone's Accessibility Options tends to be in a senior position and less comfortable with technology. They would have difficulty following the instructions to bypass the challenge code and use OTP passwords instead.

    Also, as Steve mentioned, we've also seen the spinning timer occasionally blocking the two-digit code depending on screen scaling and size. At this point, we are just testing a small number of users, and it will be interesting to see what would happen when Microsoft decides to enable number matching for everyone worldwide.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.