Is anyone else annoyed by the Microsoft's Account two-factor authentication?


Recommended Posts

Is anyone else annoyed by the Microsoft's Account two-factor authentication?

 

14786142970_872e7b0656_b.jpg

 

 

 

14972473422_41a38f403f_o.jpg

 

I've had numerous customer almost get locked out of their account already. I understand that Two-authentication is great everything but the following is the issue I have with the way Microsoft is doing it.

 

One day I got a call about a woman who all of the sudden started getting this message (the 1st photo). They wouldn't let her enter her account until she would validate she was the owner of her own account and enter the code they would send her. The issue was she was at the lakes for the summer and the recovery email she had on the account was from her home ISP which was currently disconnected while gone.

 

So the best we could do is create her a new gmail address which she could use (on photo 2) just to authenticate her account and to change her security information. They say that it takes 30 days for this to take in effect.

 

But what about this

 

Hacker, hacks an account which isn't used a lot. They tell Microsoft, I cant authenticate with the email on file, use this one. So he enters his email address and they send the hacker a link which he clicks and resets the security information. Now normally it takes 30 days for this to take in effect but the person who's account he logged into doesn't use it once every 60 days.

 

It's just something about how the implicated their two factor authentication which just annoys me.

I've run into this recently where the second account I had tied to it hadn't been used in years and being that it was also a hotmail account meant it got auto deleted long ago. No way for me to get full access to edit my account unless I jump through the 30 day hoop. -_-

Not sure what the problem is here. You're the one who 1. switched on two-factor authentication and 2. elected to use e-mail addresses for authentication. It's your job to make sure you keep those e-mail accounts alive. If you can't, don't use e-mail addresses and use another option (mobile, app, etc.).

For me, I do the two-factor authentication by having it send me a text message. For me, I get logged out of my account a lot. Especially Skype. Skype likes to randomly log me out about every 3rd time I start it up on either my computer or my phone. So every single time I log in, even when I check the "Don't ask for codes while using this device" box, they still require me to go through the hoops and have it send me a text message.

 

It'd be more fine if after I log in, the webpage says "Okay, sent a text message to your phone (***)-***-**56" or something like that. But instead, they have to ask me how I'd like to verify my account (fortunately, the text message option is the default), and then they ask me to put in the last four digits of my phone number before sending the text messge, which is just an annoying extra step.

 

On paper, it seems like a good idea, but... if someone else were to steal my phone, it'd be as simple as four taps from the home screen to get to my full phone number. Simply asking for the last four digits doesn't really seem to be a way to stop anybody. If they wanted me to verify some personal information, why not choose something that's not so easily accessible from my physical device?

Had a guy call me today using all sorts of profanity towards this. It started a month ago and he just got around to calling. It started saying unless you validate we aren't letting you in, well the recovery address was his last name at hotmail.com but he claims he doesn't have that address so maybe he mistyped it.

 

So now he entered his friends email address to send the email to and to change his security into ...blah blah.. the whole thing could be done better.

There is an option to remember the device and add it to the trusted devices, but there is also the option to remove all trusted devices on the account. If a hacker gains access, they can simply revoke all of your devices before changing the details.

You can always use a two factor authenticator program for Android, Windows Phone, iOS, Blackberry, Windows, Linux or OSX, and you're good.

yes I have had it not trust me for the 30 day waiting period which affected my Surface Pro, Windows Phone, Xbox 360 along with services Onedrive & Hotmail after getting a new Windows Phone & #  when my old was the main verification.

 

You can always use a two factor authenticator program for Android, Windows Phone, iOS, Blackberry, Windows, Linux or OSX, and you're good.

 

 

The exploit warwagon mentions would circumvent the 2-factor app, as you enter the code at the same point as you would enter the email security code.

This is actually pretty worrying for those who do not access their account often, or never keep it up to date with their newest email address or mobile number.

Not sure what the problem is here. You're the one who 1. switched on two-factor authentication and 2. elected to use e-mail addresses for authentication. It's your job to make sure you keep those e-mail accounts alive. If you can't, don't use e-mail addresses and use another option (mobile, app, etc.).

Pretty much this.

For me, I do the two-factor authentication by having it send me a text message. For me, I get logged out of my account a lot. Especially Skype. Skype likes to randomly log me out about every 3rd time I start it up on either my computer or my phone. So every single time I log in, even when I check the "Don't ask for codes while using this device" box, they still require me to go through the hoops and have it send me a text message.

I never get asked that and I have two factor turned on and I login to skype like once a month. I hate the program and try to avoid using it as much as humanely possible. The only time I've ever seen the "please enter the code to login" was when I logged into it using another computer.

Not sure why it asks you so often.

On paper, it seems like a good idea, but... if someone else were to steal my phone, it'd be as simple as four taps from the home screen to get to my full phone number. Simply asking for the last four digits doesn't really seem to be a way to stop anybody. If they wanted me to verify some personal information, why not choose something that's not so easily accessible from my physical device?

If someone had your phone then the entire thing is worthless anyways since they'll get the text message and be able to login. The 4 digits thing is to verify that it's actually you and not someone else.

There is an option to remember the device and add it to the trusted devices, but there is also the option to remove all trusted devices on the account. If a hacker gains access, they can simply revoke all of your devices before changing the details.

And? That's the way it is with every two-factor authentication. If someone gets access to your device and knows your password well nothing can really protect you anymore.

It's like if someone got access your computer then apart from like encryption, nothing is going to protect you.

  • Like 2

 

 
 

 

The exploit warwagon mentions would circumvent the 2-factor app, as you enter the code at the same point as you would enter the email security code.

This is actually pretty worrying for those who do not access their account often, or never keep it up to date with their newest email address or mobile number.

 

 

Yep. This is why most implementations of 2FA only allow you to use either a recovery code, or a code from the mobile authenticator app. Most will also add text based codes as a backup. The idea is to require access to another device which only the true user should have access to. When implemented like this, if you lose access to recovery codes, your phone number, and the mobile authenticator app, you lose access to your account.

 

The images in the original post aren't from a 2FA enabled account though. This is just something that Microsoft pops up on devices it doesn't recognize for accounts without 2FA enabled.

No. Because it's the user who is at fault here. I have it turned on and use code generator for it. If that fails, I can always recover using a secondary email or phone/text.

These things work if you pay attention to what you are doing.

In general i think its a good thing, the customers complaining are the ones that likely need protection from themselves.

 

The only problem i have with Microsoft's two factor authentication are devices / services that don't support codes generated by an authentication app, and require a one time use password.

It's a right pain having to log in to account.live.com, create a one time use password then entering it on a friends Xbox 360 for example. It would be nice if Microsoft updated all their products and services to support codes generated by authentication apps.

 

Google Authenticator works fine for any Microsoft services that support authentication apps on Android and iOS.

It really isn't two factor authentication per se. It's a way to have a current medium like phone or secondary email address so they can contact you in the event you lose access (forgotten password most likely) to the Microsoft account.

 

When you have your security info updated and verified, you can still log in using only your Microsoft ID and password. There is a separate option to enable true two-factor authentication.

 

InsaneNutter above is right. This is aimed towards people that will not have any means to recover an account once their password is lost or forgotten.

 

This security authentication is required is when you sign in from a previously unknown (to Microsoft) device. On Windows 8-8.1 you don't need this when using IE but the first time you try log in from another browser, you will get prompted for a code. Once this is done, it's not required anymore.

 

I've had many clients in the past that couldn't remember the password and they couldn't get a reset because of outdated/missing secondary email address or a phone number on the account.

 

The only downside of adding security info is the 30 day waiting period but it works on the user favor if they didn't trigger the request to change info or change password.

And? That's the way it is with every two-factor authentication. If someone gets access to your device and knows your password well nothing can really protect you anymore.

It's like if someone got access your computer then apart from like encryption, nothing is going to protect you.

 

However, you do not need access to any of their devices, you only need their password. Try it out for yourself. You'll see resetting the security info on a MS live account is a lot easier (but more time consuming) than other 2-factor authentications. At least with Google, and various MMO 2-factor authentications, you need to answer the security questions you would have been forced to enter when setting up the account.
 

 

The images in the original post aren't from a 2FA enabled account though. This is just something that Microsoft pops up on devices it doesn't recognize for accounts without 2FA enabled.

 

Even with the 2-factor authentication app, you only have to click the "get a code in a different way" link to either try the email/text code or enter the recovery code. Once you say no to both, the security info can be replaced and after 30 days you can login using those details. Granted, this is not an issue for anyone who regularly uses their account or have set up email/text security alerts, but for those who don't this could be a problem.

I've had it working perfectly with Microsoft, Google, Dropbox, and other services. I think it's just your approach to 2FA. 

 

I use Authy to sync/get my 2FA codes.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Frankly, I blame whoever is writing such articles. "A big improvement/update and/or new feature is now available to everyone! Also, use this unofficial tweak tool to enable it because it actually isn't available to you yet officially and might not in fact even be entirely ready or whatever, hence why it is perhaps not enabled for you*. But it's great and you should enable it!" I mean there's nothing wrong with sharing info about some feature you might need to enable via unofficial means, of course. It's just that these articles tend to essentially end up being two news pieces in one, and one of them tends to be a bit misleading. (*Yes, yes, the "it's a controlled rollout!" thing. Not a fan of that one either. The argument, not the actual rollout.)
    • Thank you. Will do. I read in the release notes that editor config might be at play here.
    • Actually, I think even Microsoft doesn't know how to control it
    • OpenAI is making Codex more useful in Chrome and the cloud by Pradeep Viswanathan OpenAI's Codex now has more than 5 million users, up nearly 4x from earlier this year. To further accelerate Codex's growth among developers, OpenAI today announced that it has agreed to acquire Ona, a company that builds secure cloud execution and orchestration technology for developers. Ona will enable developers to run Codex with persistent and controlled cloud infrastructure for long-running agentic workflows. Right now, most Codex execution happens locally on developers' laptops and PCs, and the agents work continuously for hours. Through Ona, OpenAI aims to make Codex agents keep working for days without being tied to a user’s local machine or an active session. This will be an important capability for enterprises that want to deploy AI agents in production while maintaining control over infrastructure, data, security boundaries, credential scope, logging, and review workflows. Like any acquisition, the deal is still subject to customary closing conditions, including regulatory approvals. Until the deal closes, OpenAI and Ona will continue to operate as separate companies. After closing, Ona’s team will join the Codex team to improve developer workflows. Alongside the Ona acquisition announcement, OpenAI today introduced a few Codex updates. Developers can now save Codex rate limit resets and use them later instead of losing them when they are not needed immediately. OpenAI is also adding a referral option where users can invite a friend to Codex and get a saved rate limit reset. OpenAI today also announced a developer mode for browser use in Chrome and the Codex in-app browser. With this mode, Codex can use the Chrome DevTools Protocol to debug web apps, inspect pages, and work more directly with browser-based development workflows. Developers can use this when they want Codex to profile JavaScript, inspect console output and network traffic, examine web page states including the DOM and applied styles, and more.
    • Camtasia 2026.1.3 by Razvan Serea TechSmith Camtasia is the complete professional solution for high-quality screen recording, video editing and sharing. Camtasia 2026 makes editing your videos easier, and faster than ever. The new editor is packed with enhanced video processing, all-new production technology, an innovative library, and stock videos and other creative assets to help you create more polished, professional videos. No video experience needed. Anyone can create informative, engaging videos. Create professional, eye-catching videos: Add special video effects - Apply Behaviors that are perfectly designed to animate your text, images, or icons. Get a crisp, polished look without being a professional video editor. Drag-and-drop your edits - What you see is what you get. Every effect and element in your video can be dropped and edited directly in the preview window. And you can edit at resolutions up to beautiful 4K, for clear video at any size. Get exceptional performance - Camtasia takes full advantage of your computer’s processor with 64-bit performance. You’ll get fast rendering times and enhanced stability—even on your most complex projects. Camtasia 2026.1.3 changelog: Feature Updates Improved keyboard navigability in tool panels. Improved screen reader accessibility of headings in Preferences. Tool panels can now be resized using a keyboard-navigable control. Updated color of folder icon in User Library tab for better visibility. Grouped media now render a composite waveform considering all audio media within that group. Added Long Path Aware to the manifest of Editor and Recorder. Performance Improvements Improved performance for editing groups on the timeline. Improved the project loading performance when timeline has lots of trec media with cursor data. Updates for IT Administrators Updated cpp-httplib from 0.38.0 to 0.43.3. Updated expat from 2.7.4 to 2.8.0. Updated freetype from 2.13.3 to 2.14.3. Updated harfbuzz from 13.0.1 to 14.2.0. Updated libpng16 from 1.6.55 to 1.6.58. Updated pango from 1.57.0 to 1.57.1. Updated girepository from 2.86.3 to 2.88.0. Updated pcre2-posix from 10.47.0 to 12.0.2. Added new harfbuzz-gpu.dll. Updated FFmpeg from 7.1.1 to 7.1.2. Updated aom from 3.11.0 to 3.13.1. Updated dav1d from 1.5.0 to 1.5.1. Updated ogg from 1.3.5 to 1.3.6. Updated SDL2 from 2.32.4 to 2.32.10. Updated zlib from 1.3.1 to 1.3.2. Updated Nalpeiron binaries to version 4.4.69.3. Bug Fixes Fixed an issue which prevented some user submitted crash reports from being sent. Fixed a potential memory leak when decoding HEVC or VP9 video. Fixed a potential crash when trying to delete a range selection on a magnetic track. Fixed a bug with the Properties Panel showing stale properties when only a caption is selected on the timeline. Fixed an issue that could prevent the Opacity and Blur properties from being changed in the Background Removal effect. Fixed an issue where larger Camtasia online projects may fail to open in Camtasia Editor. Table of contents thumbnails are no longer created for Smart Player exports with no table of contents. Fix resetting skew revert to revert just skew and not scale as well. Fixed editing in Snagit with snagX file with Unicode characters. Fixed a bug where grouped visual media could be cropped in some cases. Fixed importing SnagX files with Unicode characters. Localization fixes. Download: Camtasia 2026.1.3 | 309.0 MB (Shareware) View: Camtasia Homepage | Tutorials | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
  • Recent Achievements

    • One Month Later
      Jamswaz earned a badge
      One Month Later
    • Week One Done
      Jamswaz earned a badge
      Week One Done
    • Rookie
      Marzoid went up a rank
      Rookie
    • Community Regular
      coch went up a rank
      Community Regular
    • One Year In
      slackerzz earned a badge
      One Year In
  • Popular Contributors

    1. 1
      +primortal
      511
    2. 2
      PsYcHoKiLLa
      188
    3. 3
      +Edouard
      157
    4. 4
      Steven P.
      83
    5. 5
      ATLien_0
      75
  • Tell a friend

    Love Neowin? Tell a friend!