A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Dear @Mulualem G/Michael
Thank you for reaching out. I understand your concern, especially since multiple employees are receiving unexpected MFA verification codes without initiating any sign-in requests.
This behavior does not necessarily indicate a Microsoft service issue or a Passkey/FIDO2 rollout. Unexpected MFA codes can result from repeated sign-in attempts, authentication policy changes, or application-related authentication requests.
I recommend checking the following:
- Review Microsoft Entra sign-in logs: Go to Micrososft 365 Admin Center > Microsoft Entra Admin Center > Entra ID > Monitoring & health > Sign-in logs. Filter by the affected users and the time the codes were received. Check the IP addresses, applications, sign-in status, and Authentication Details to identify what triggered the MFA requests. Microsoft documents the administrator process here: What are Microsoft Entra sign-in logs?
- Check recent authentication policy changes: Review Entra ID > Authentication methods > Policies and your Conditional Access policies. Check the audit logs for any recent changes involving MFA, Passkeys/FIDO2, or authentication requirements.
Check Microsoft service health: In the Microsoft 365 Admin Center, navigate to Health > Service health to see whether Microsoft has reported any authentication-related incidents affecting your organization.
Review potential security concerns: If the sign-in logs show unfamiliar IP addresses or suspicious attempts, investigate immediately. I also recommend reminding employees not to share verification codes or approve unexpected MFA requests.
Regarding your Passkey/FIDO2 question, enabling or disabling these authentication methods does not normally generate unsolicited one-time verification codes for all employees. However, changes to authentication policies or registration requirements may cause users to encounter additional authentication prompts during legitimate sign-ins.
To help me narrow down the cause, could you please confirm:
Are employees receiving these codes via SMS, email, or Microsoft Authenticator?
- Did all affected employees start receiving them at approximately the same time?
Were there any recent changes to Conditional Access, MFA, or Passkey/FIDO2 policies?
If possible, please also share a sample sign-in log entry from an affected user, with personal information removed.
I hope this helps you identify whether the behavior is related to a configuration change, a Microsoft service issue, or unexpected sign-in activity.