HomeSecurityMicrosoft Authenticator: Automatically blocks suspicious MFA notifications

Microsoft Authenticator: Automatically blocks suspicious MFA notifications

Microsoft has introduced a new feature in the Authenticator app to block MFA notifications that appear suspicious, based on specific checks performed during account.

See also: Retool attributes breach to Google Authenticator MFA cloud sync feature

Microsoft Authenticator: Automatically blocks suspicious MFA notifications

Microsoft Authenticator is an app that offers multi-factor authentication, password autofill, and password-free sign- in to Microsoft accounts

When a user attempts to log in to an account protected by multi-factor authentication (MFA), the Authenticator app sends a notification to the user's device to allow or deny access.

Alternatively, the app generates a temporary password for users to manually log in to their account.

Hackers have been known to exploit the push notification feature by making a large number of login attempts to the target account, often at inappropriate times, hoping to confuse or fatigue the recipients. If the user approves a request, the attacker gains access to the account and can modify the login protection settings to block the legitimate user.

For added security, Microsoft introduced “number matching” in May, a mechanism where the user must enter a number displayed on the login screen in the Authenticator app to authorize the connection.

See also: Google Authenticator: Now synchronizes one-time codes in the cloud

Microsoft Authenticator: Automatically blocks suspicious MFA notifications

While this measure has reduced the effectiveness of MFA attacks, it doesn't prevent the annoying notifications from being generated per se. To combat this malicious activity, Microsoft has added new features that examine details about login attempts, such as whether the request is coming from an unknown location or shows signs of abnormality, to block the notification from appearing.

Instead, users receive a message prompting them to open the Authenticator app and enter a provided code. Login notifications are still generated and are available through the Authenticator app if the user needs to review and review them.

Since the new feature was rolled out at the end of September, Microsoft has blocked over six million MFA notifications that were likely to have come from hackers.

See also: Microsoft Authenticator: End of support for Apple Watch

Microsoft continues to invest in security and evolve Authenticator to provide a more secure and easier-to-use verification tool. With these latest updates, the Authenticator app becomes even stronger in protecting user accounts from phishing attacks and other forms of malicious activity. Users can feel secure knowing that Microsoft is committed to protecting their information and providing a high level of security.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS