#Possible Crisis - Authenticator Just Gave me an unwanted Code

21 messages · Page 1 of 1 (latest)

limber plume
#

My phone just got a notification for a code, even though I haven't tried to log in. Has someone somehow gotten my password???

ripe pendant
#

Might have, but probably stopped via 2FA. Change your password and log out of everything

limber plume
#

How do I do that?

sick vale
#

one sec, trying to find the direct link

#

look for failed attempts

limber plume
#

Seems like I found it, but none of the devices seem to be out of the ordinary.

#

Two at 6 and 6:01 PM + one now, all three are me and successfull.

#

Changed the passord just in case, but do I then need to turn off and on 2FA again and get new backup codes + app password?

sick vale
#

but I would recommend disabling SMS 2FA

limber plume
#

oh?

sick vale
#

SMS 2FA is way less secure than any other 2FA methods since SMS is inherently insecure SweatSmileFluent

limber plume
#

Don't understand why my Auth. app alerted me of a sign in verification with a choice of three set of codes, when I didn't log in or do anything new and nether the Activity or Devices area of Account Microsoft website shows any sign of new devices that doesn't belong to me or any sign in other than my own.

limber plume
#

I get it now, for some reason Microsoft have changed it to when you log in to new places, browsers, IPs etc. it defaults to "ask for a code in Authenticator" now where you can easily jump in with the app by verifying the login instead of just writing in your password. So nobody had my password or access to my account to begin with, just entered my email and pressed "login with code" nonsense.

sick vale
#

asking for more than "just your password"

limber plume
#

Have had 2FA activated for years, of course its a nice and secure feature. However, a little weird to have that as default instead of doing that after writing in your password like it used to.

sick vale
#

I don't even have a password anymore