Microsoft 365 features that help users manage their subscriptions, account settings, and billing information.
Hi,
I understand why this would be concerning. Receiving repeated Microsoft Authenticator prompts can certainly feel alarming, especially when they continue after you’ve changed your password. Based on your description, this doesn’t necessarily indicate that someone knows your password or has successfully authenticated.
For Microsoft personal accounts, a passwordless sign-in attempt can be initiated once an account identifier is entered. The authentication request is then sent to the registered Authenticator app, but the sign-in cannot complete unless the person approves the request and successfully completes number matching (or any other required verification). Changing your password doesn’t stop these prompts because they aren’t dependent on password authentication. They are separate passwordless sign-in attempts targeting the account identifier itself.
That said, repeated unsolicited prompts should always be denied. If you continue receiving them, I also recommend:
- Keep number matching enabled and never approve unexpected requests.
- Review recent sign-in activity at your Microsoft account’s Recent activity page to check for unsuccessful attempts and report any activity you don’t recognize.
- If you’re using an email alias, consider making a different alias your primary sign-in alias and disable sign-in for the publicly known alias. This can reduce unsolicited authentication attempts against the exposed email address.
Regarding your broader question about whether this behavior is intended or whether it’s an ongoing abuse campaign, Microsoft hasn’t published information indicating a vulnerability that allows attackers to bypass authentication. The behavior you’ve described is consistent with how passwordless authentication requests are initiated, although I understand your concerns about the potential for notification fatigue.
If you believe the current implementation should include additional abuse protections such as stronger rate limiting or other mitigations, I’d encourage submitting that feedback through the Microsoft Feedback Portal, as security design feedback is monitored by the appropriate product teams.
I hope this helps clarify what’s happening.