Is Microsoft seriously allowing anyone on the internet to trigger passwordless authentication prompts for consumer Microsoft accounts just by knowing the email address?

Janik Steiner 0 Reputation points
2026-07-13T11:58:29.4866667+00:00

Several colleagues and I have been receiving repeated Microsoft Authenticator prompts from locations all across Europe, including Bosnia, Ukraine, and Germany.

These are not normal MFA prompts following a successful password entry. They are passwordless sign-in requests.

We changed the passwords to completely new, unique passwords, signed out all sessions, and reviewed the account security settings. The prompts still continue.

This strongly suggests that an attacker does not need to know the password at all. They only need the public Microsoft account email address, select passwordless sign-in, and Microsoft delivers an authentication prompt directly to the victim’s registered device.

Is this seriously Microsoft’s intended security design?

Has Microsoft effectively exposed a global, unauthenticated push-notification endpoint where any random person, botnet, or attacker can spam Microsoft Authenticator users as long as they know the account identifier?

Number matching may prevent a simple accidental approval, but it does not prevent:

  • MFA fatigue attacks
  • repeated harassment
  • notification denial-of-service
  • social engineering combined with phone calls
  • automated mass targeting of leaked email addresses

A Microsoft account email address is obviously not a secret. Treating knowledge of that address as sufficient to initiate a security-sensitive push notification seems completely incompatible with basic abuse prevention and modern identity security principles.

Why is there apparently no meaningful rate limiting, abuse detection, source restriction, or requirement for the requester to prove any prior knowledge or possession before Microsoft sends the prompt?

And why does changing the password have no effect whatsoever on these requests?

So the direct question is:

Is this really Microsoft’s intended behaviour, or is there currently a vulnerability or abuse campaign affecting passwordless authentication for personal Microsoft accounts?

Because if this is working as designed, then the design is fundamentally broken from an abuse and MFA-fatigue perspective.

Microsoft 365 and Office | Subscription, account, billing | For business | Other
0 comments No comments

1 answer

Sort by: Most helpful
  1. Ana Le 1,890 Reputation points Independent Advisor
    2026-07-13T12:25:20.0966667+00:00

    Hi,

    I understand why this would be concerning. Receiving repeated Microsoft Authenticator prompts can certainly feel alarming, especially when they continue after you’ve changed your password. Based on your description, this doesn’t necessarily indicate that someone knows your password or has successfully authenticated.

    For Microsoft personal accounts, a passwordless sign-in attempt can be initiated once an account identifier is entered. The authentication request is then sent to the registered Authenticator app, but the sign-in cannot complete unless the person approves the request and successfully completes number matching (or any other required verification). Changing your password doesn’t stop these prompts because they aren’t dependent on password authentication. They are separate passwordless sign-in attempts targeting the account identifier itself.

    That said, repeated unsolicited prompts should always be denied. If you continue receiving them, I also recommend:

    • Keep number matching enabled and never approve unexpected requests.
    • Review recent sign-in activity at your Microsoft account’s Recent activity page to check for unsuccessful attempts and report any activity you don’t recognize.
    • If you’re using an email alias, consider making a different alias your primary sign-in alias and disable sign-in for the publicly known alias. This can reduce unsolicited authentication attempts against the exposed email address.

    Regarding your broader question about whether this behavior is intended or whether it’s an ongoing abuse campaign, Microsoft hasn’t published information indicating a vulnerability that allows attackers to bypass authentication. The behavior you’ve described is consistent with how passwordless authentication requests are initiated, although I understand your concerns about the potential for notification fatigue.

    If you believe the current implementation should include additional abuse protections such as stronger rate limiting or other mitigations, I’d encourage submitting that feedback through the Microsoft Feedback Portal, as security design feedback is monitored by the appropriate product teams.

    I hope this helps clarify what’s happening.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.