Receiving a single-use Microsoft verification code that was not requested usually means one of the following:
- Someone is trying to access the account and entered the email or phone number.
- Someone accidentally typed the wrong email or phone when trying to sign in.
- A code that was legitimately requested earlier was delayed and arrived late.
Do not use or reply to any verification code that was not requested. Without the code, an attacker cannot complete sign-in, so the account remains protected.
To improve security and reduce unwanted codes, enable a passwordless sign-in method (for example, Windows Hello, Microsoft Authenticator, SMS/Email codes, or a physical security key). Passwordless methods are more secure than passwords because they rely on something owned or physically present rather than a guessable or phishable password.
If the email containing the code is from @accountprotection.microsoft.com, it is a legitimate Microsoft notification. However, still ignore the code if it was not requested.
If unrequested codes continue frequently, review and harden account security (for example, updating security info and using passwordless sign-in) to ensure the account stays protected.
References: