Treat the message as suspicious and keep it in Junk.
For legitimate Microsoft account verification codes:
- Email verification codes are sent only to the primary alias or a security email that was explicitly added as a way to verify sign-in.
- Valid verification-code emails come from an
@accountprotection.microsoft.comaddress.
If the message does not come from @accountprotection.microsoft.com, or it claims a code was requested when no sign-in or security action was performed, it should be treated as junk/phishing. Do not click any links, open attachments, or reply.
As an extra safety step, add @accountprotection.microsoft.com to the safe senders list so real verification emails go to the Inbox, and continue to let suspicious ones go to Junk.
References: