Good news from Microsoft. The company said that users who have multi-factor authentication enabled for their accounts are able to stop 99.9% of automated attacks.
Of course, this position doesn't just apply to Microsoft accounts , but to any profile, site , or online service that uses this method of verification. That's why the company recommends using multi-factor authentication wherever it's available.

A company spokesperson said that using very long passwords or removing security codes that have been compromised doesn't actually help from a security perspective. These seem to be theories of the past.
Alex Weinert, Group Program Manager for Security and Protection at Microsoft, said that in the past they had worked in this very area. That is, in banning passwords that had been compromised. The result was that any user who experienced an onlinewas immediately informed that they had to change their credentials. At this point, it was observed that even when users did what they were told and changed their passwords frequently, hackers continued to attack normally.
So Microsoft teams came to the conclusion that the complexity of passwords doesn't really matter. Hackers now have different methods at their disposal to carry out attacks and most of the time the password doesn't matter.
With this knowledge, Weinert suggests multi-factor authentication as a solution for 99.9% of cases. However, he leaves that small 0.1% for more specialized cases of sophisticated and rarer attacks.

Of course, Microsoft isn't the first company to come to this conclusion. Last May, Google said that users who added a recovery phone number to accounts also improved their account security.
For all these reasons, when both Google and Microsoft recommend the same thing for improving security, it's probably the right time to consider their advice.
