Error code 399287 when requesting SMS for MFA

Elena Burnham 0 Reputation points
2026-07-01T11:22:49.4566667+00:00

We're getting the following error when requesting an OTP code via SMS text message:

Error Code: 399287

Request Id: 5a678763-a581-4813-ac6c-12ef65c10500

Correlation Id: 93a36e8f-1f4e-4a2e-92e8-2dd8b41addff

Timestamp: 2026-07-01T09:58:24Z

Please remove the phone number (+XXX XXXXXXXX34‎) from the bad reputation list.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments

1 answer

Sort by: Most helpful
  1. Jerald Felix 17,385 Reputation points Volunteer Moderator
    2026-07-04T17:04:39.21+00:00

    Hello Elena Burnham,

    Greetings! Thanks for raising this question in the Q&A forum.

    Error code 399287 with the underlying result value "BadReputation" means Microsoft Entra ID's telephony fraud protection system has flagged your phone number and blocked it from receiving SMS (and typically voice call) verification codes. This is a fraud prevention control aimed at abuse patterns like International Revenue Share Fraud (IRSF) rather than anything wrong with your number, carrier, or device, and it is applied at the Microsoft service level, not inside your tenant configuration. Because of that, there is no admin setting, Conditional Access change, or user-side retry that will clear it. The flag has to be removed on Microsoft's backend.

    1. Confirm there is no self-service path first Check the Microsoft Entra admin center sign-in logs for the affected user to confirm the failure lines up with this error and capture the Correlation ID and timestamp for your records, since support will ask for these.
    Microsoft Entra admin center > Identity > Monitoring & health > Sign-in logs
    
    1. If another Global Administrator exists, use them as an interim workaround while support resolves the flag A second admin can remove the phone-based method and issue a Temporary Access Pass so the affected user can sign in once and register a different method, such as Microsoft Authenticator, in the meantime.
    Microsoft Entra admin center > Identity > Users > [affected user] > Authentication methods > Require re-register multifactor authentication
    Microsoft Entra admin center > Identity > Users > [affected user] > Authentication methods > Add authentication methods > Temporary Access Pass
    

    Be careful with "Require re-register" since it can clear more than just the phone method, so make sure the user has a safe way back in (the TAP) before applying it.

    1. Open a Microsoft Support case to have the phone number's reputation flag cleared This is the actual fix, since only Microsoft's Data Protection / engineering team can remove the "BadReputation" block on the backend.
    Microsoft Entra admin center or Azure portal > Help + support > New support request
    Issue type: Multi-factor authentication (MFA)
    Details to include: tenant ID, affected phone number, error code 399287, Request Id, Correlation Id, timestamp
    

    If you cannot sign in at all to open a ticket because SMS is your only working method, use another admin's account if one exists, or reach Microsoft Support by phone and clearly state that SMS/voice MFA is failing with error 399287 due to a phone number reputation block, since this specific phrasing gets you routed to the right team faster.

    1. Once resolved, stop relying on SMS or voice as the only MFA method Telephony-based methods are more exposed to this kind of fraud-protection blocking than app-based methods. After support clears the flag, register Microsoft Authenticator or a FIDO2 security key/passkey as your primary method, and keep SMS only as a secondary fallback rather than your sole method, especially for any administrator account.

    Reference documentation:

    If this answer helps you kindly accept the answer which will help others who have similar questions. Best Regards, Jerald Felix.Hello Elena Burnham, Greetings! Thanks for raising this question in the Q&A forum.

    Error code 399287 with the underlying result value "BadReputation" means Microsoft Entra ID's telephony fraud protection system has flagged your phone number and blocked it from receiving SMS (and typically voice call) verification codes. This is a fraud prevention control aimed at abuse patterns like International Revenue Share Fraud (IRSF) rather than anything wrong with your number, carrier, or device, and it is applied at the Microsoft service level, not inside your tenant configuration. Because of that, there is no admin setting, Conditional Access change, or user-side retry that will clear it. The flag has to be removed on Microsoft's backend.

    1. Confirm there is no self-service path first Check the Microsoft Entra admin center sign-in logs for the affected user to confirm the failure lines up with this error and capture the Correlation ID and timestamp for your records, since support will ask for these.
    Microsoft Entra admin center > Identity > Monitoring & health > Sign-in logs
    
    1. If another Global Administrator exists, use them as an interim workaround while support resolves the flag A second admin can remove the phone-based method and issue a Temporary Access Pass so the affected user can sign in once and register a different method, such as Microsoft Authenticator, in the meantime.
    Microsoft Entra admin center > Identity > Users > [affected user] > Authentication methods > Require re-register multifactor authentication
    Microsoft Entra admin center > Identity > Users > [affected user] > Authentication methods > Add authentication methods > Temporary Access Pass
    

    Be careful with "Require re-register" since it can clear more than just the phone method, so make sure the user has a safe way back in (the TAP) before applying it.

    1. Open a Microsoft Support case to have the phone number's reputation flag cleared This is the actual fix, since only Microsoft's Data Protection / engineering team can remove the "BadReputation" block on the backend.
    Microsoft Entra admin center or Azure portal > Help + support > New support request
    Issue type: Multi-factor authentication (MFA)
    Details to include: tenant ID, affected phone number, error code 399287, Request Id, Correlation Id, timestamp
    

    If you cannot sign in at all to open a ticket because SMS is your only working method, use another admin's account if one exists, or reach Microsoft Support by phone and clearly state that SMS/voice MFA is failing with error 399287 due to a phone number reputation block, since this specific phrasing gets you routed to the right team faster.

    1. Once resolved, stop relying on SMS or voice as the only MFA method Telephony-based methods are more exposed to this kind of fraud-protection blocking than app-based methods. After support clears the flag, register Microsoft Authenticator or a FIDO2 security key/passkey as your primary method, and keep SMS only as a secondary fallback rather than your sole method, especially for any administrator account.

    If this answer helps you kindly accept the answer which will help others who have similar questions.

    Best Regards,

    Jerald Felix.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.