Why are multiple users receiving unrequested OTPs via text even if their default MFA is Authenticator app?

Besfort Zymberi 185 Reputation points
2025-06-11T17:41:56.9266667+00:00

Several users reporting having received OTP text messages from Microsoft that they did not request. No suspicious logins observed. Issue with Microsofts service?

Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

3 answers

Sort by: Most helpful
  1. Logan 30 Reputation points
    2025-06-11T19:10:27.89+00:00

    In Entra, select "Security" > "Authentication Methods" > "Policies" > "SMS" and make sure 'Use for Sign in' is not enabled.

    If enabled, this setting means that people can log in with a cell phone number + SMS code instead of an email and password. These are likely the the reason you're receiving the verification messages, especially if you're not seeing sign in logs associated with the codes. There appears to be some sort of bad actor campaign targeting this login method, for what purpose, remains to be seen.

    The reason you're not seeing a sign-in log is because the account is only being authenticated with a username (the cell phone number in this case.) No password (the text code) is being entered.

    4 people found this answer helpful.

  2. Eric Nguyen 1,025 Reputation points Independent Advisor
    2025-06-12T08:43:56.1733333+00:00

    Hi @Besfort Zymberi ,

    Thank you for contacting Q&A Forum. I would like to provide my findings and proposed solution:

    We understand your concern regarding unexpected OTP messages via SMS. Here’s what to check:

    Disable SMS authentication – In the Microsoft Entra admin center, go to Security → Authentication methods → Policies, locate Text message (SMS), and set Enable to No.

    Confirm account type – Are you using an individual Microsoft account (MSA) or a Work/School account (Microsoft Entra ID)? If it’s an MSA, sign-in logs won’t be visible in Entra, and unauthorized access could be the cause.

    Check recent sign-ins – If you suspect unusual activity, update your password and review security settings https://account.microsoft.com/security.

    Please note: We do not support personal accounts in the Work & School tenant. If you need further help securing an individual account, please contact Microsoft Support.

    Kindly let me know if this work for you and please let me know if you have any further questions.

    If I have answered your question, please accept this as answer as a token of appreciation and don't forget to give a thumbs up for "Was it helpful"!

    Best regards,
    Eric


  3. Raja Pothuraju 23,465 Reputation points Microsoft External Staff Moderator
    2025-06-16T15:34:14.16+00:00

    Hello Besfort Zymberi,

    As described, several users have reported receiving unexpected SMS codes for multi-factor authentication (MFA) without initiating any sign-in attempts. Notably, there are no corresponding sign-in logs related to these MFA prompts. The messages appear to originate from legitimate Microsoft SMS numbers, and some affected users do not have SMS configured as an MFA method.

    On June 11, 2025, Microsoft detected an anomalous actor attempting account enumeration using phone numbers. If these phone numbers were registered with SMS as a single-factor authentication method on an Entra account, the Entra user received an unexpected SMS containing the authentication code to log in.

    Our engineering team is investigated this activity and mitigated the issue by addressing all of the aspects.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.