Microsoft thinks it has a new way to make 2FA security better, and less annoying for you

Person writing on computer
(Image credit: Glenn Carstens-Peters / Unsplash)

Microsoft has changed the way its authenticator app works, in an effort to make it more secure by preventing multi-factor authentication (MFA) fatigue attacks.

When receiving a push notification from Microsoft Authenticator on their secondary device, such as a smartphone, to verify a login attempt, users will now have to input a two digit code shown on the primary device. This means that they cannot accept a login attempt unless they can actually see the login screen.

In MFA attacks, the hope is that users blindly verify login attempts after being bombarded with them, just to make them stop or by mistake after being worn down. This method has been quite successful in penetrating large corporations - including Microsoft itself - once hackers have stolen a worker's initial login credentials.

Rolling out now

On the company's Learn website, Microsoft explained that, "Number matching is a key security upgrade to traditional second factor notifications in Microsoft Authenticator. We will remove the admin controls and enforce the number match experience tenant-wide for all users of Microsoft Authenticator push notifications starting May 8, 2023."

It also said that various services will be being employing this new change, and that some services may see number matching and others won't. But before Microsoft removes the admin controls, users can manually make the switch by navigating to Security > Authentication methods > Microsoft Authenticator in the Azure portal.

Then, under Enable and Target, you can choose which users it will apply to, by setting the Authentication mode to Any or Push. Under the Configure tab, you'll see Require number matching for push notifications. Change the status to Enable and choose who it applies to, then click save.

Microsoft also explains how you can use Graph APIs to enable the new number matching feature for certain groups. 

The company also noted that, "If the user has a different default authentication method, there won't be any change to their default sign-in."

"If the default method is Microsoft Authenticator and the user is specified in either of the following policies, they'll start to receive number matching approval after May 8th, 2023."

Further security measures can be take to prevent MFA fatigue attacks by restricting the number of authentication requests, alerting admins or locking accounts if that number is exceeded.

TOPICS
Lewis Maddison
Reviews Writer

Lewis Maddison is a Reviews Writer for TechRadar. He previously worked as a Staff Writer for our business section, TechRadar Pro, where he had experience with productivity-enhancing hardware, ranging from keyboards to standing desks. His area of expertise lies in computer peripherals and audio hardware, having spent over a decade exploring the murky depths of both PC building and music production. He also revels in picking up on the finest details and niggles that ultimately make a big difference to the user experience.

Read more
digital key
Microsoft really wants users to ditch passwords and switch to passkeys
A phone sitting on a laptop keyboard with the Microsoft Outlook logo on the screen.
Microsoft is changing the way logins work: here’s what that means for you
Security padlock in circuit board, digital encryption concept
MFA alone won’t protect you in 2025: the new cybersecurity imperative
Representational image of a shrouded hacker.
Getting to grips with Adversary-in-the-Middle threats
An abstract image of a lock against a digital background, denoting cybersecurity.
Building a resilient workforce security strategy
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Microsoft authentication system spoofed via phishing attack
Latest in Security
A TV remote pointing at YouTube logo
YouTube warns of phishing video using its CEO as bait
China
Microsoft says Chinese Silk Typhoon hackers are targeting cloud and IT apps to steal business data
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
BadBox malware hit after infecting over 500,000 Android devices
Webex by Cisco banner on a Chromebook
Cisco warns some Webex users of worrying security flaw, so patch now
Red padlock open on electric circuits network dark red background
AI-powered cyber threats are becoming the biggest worry for businesses everywhere
Woman using iMessage on iPhone
Apple to take legal action against British Government over backdoor request
Latest in News
An Nvidia GeForce RTX 5080 resting on an RTX 5090 on a gray crafting mat.
Corsair tells us only one of its prebuilt PCs with an RTX 5000 GPU has suffered from chip-level fault, suggesting it’s as rare as Nvidia claimed
Fujfilm GFX 50R
First Fujifilm GFX100RF images leaked in build-up to expected reveal – here’s what they tell us about the unique premium compact camera
Samsung Galaxy Z Flip 6 in blue
The Samsung Galaxy Z Flip 7 could have a Motorola Razr-style full-sized cover screen – and I think it’s about time
Spotify logo on a mobile device
Had Spotify problems recently? It's clamped down on Premium APK 'modded' apps – here's what's happening
An AMD Radeon RX 9070 XT made by Sapphire on a table with its retail packaging
Last-minute AMD RX 9070 XT stock rumors are making me hopeful for a much better launch than Nvidia’s RTX 5000 GPUs – with just one snag
eSIM
Global eSIM shipment volume surpasses half a billion units as demand keeps on growing