Do not use or respond to the code that was sent.
If a Microsoft verification or single-use code was received but not requested, the most common reasons are:
- Someone is trying to access the account.
- Someone accidentally entered the wrong phone/email when trying to sign in.
- Delivery of a code that was requested earlier was delayed.
Without the code, an attacker cannot complete sign-in, so the account remains protected as long as the code is not used.
To further protect the account and reduce unwanted codes, enable passwordless sign-in on the Microsoft account. Passwordless methods such as Windows Hello, Microsoft Authenticator, SMS or email codes, and physical security keys provide a more secure and convenient sign-in method than passwords.
For ongoing security, monitor sign-in activity and keep security info (phone, email, and sign-in methods) up to date.
References: