one-time verification code (MFA) was sent to all staff frequently

Michael 0 Reputation points
2026-10-08T11:21:20.1066667+00:00

We have noticed that a one-time verification code (MFA) was sent to all staff users unexpectedly without user requested it.

if this is related to a Microsoft-side change or service issue? Also, could this behavior be associated with the rollout, enforcement, or disabling of Passkeys/FIDO authentication?

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Oldest
  1. BabybooHN 3,465 Reputation points Independent Advisor
    2026-10-09T03:47:49.0966667+00:00

    Dear @Michael

    Thank you for reaching out. I understand your concern, especially since multiple employees are receiving unexpected MFA verification codes without initiating any sign-in requests.

    This behavior does not necessarily indicate a Microsoft service issue or a Passkey/FIDO2 rollout. Unexpected MFA codes can result from repeated sign-in attempts, authentication policy changes, or application-related authentication requests.

    I recommend checking the following:

    1. Review Microsoft Entra sign-in logs: Go to Micrososft 365 Admin Center > Microsoft Entra Admin Center > Entra ID > Monitoring & health > Sign-in logs. Filter by the affected users and the time the codes were received. Check the IP addresses, applications, sign-in status, and Authentication Details to identify what triggered the MFA requests. Microsoft documents the administrator process here: What are Microsoft Entra sign-in logs?
    2. Check recent authentication policy changes: Review Entra ID > Authentication methods > Policies and your Conditional Access policies. Check the audit logs for any recent changes involving MFA, Passkeys/FIDO2, or authentication requirements.
      Screenshot of available conditions for a Conditional Access policy in the Microsoft Entra admin center.

    Check Microsoft service health: In the Microsoft 365 Admin Center, navigate to Health > Service health to see whether Microsoft has reported any authentication-related incidents affecting your organization.

    Review potential security concerns: If the sign-in logs show unfamiliar IP addresses or suspicious attempts, investigate immediately. I also recommend reminding employees not to share verification codes or approve unexpected MFA requests.

    Regarding your Passkey/FIDO2 question, enabling or disabling these authentication methods does not normally generate unsolicited one-time verification codes for all employees. However, changes to authentication policies or registration requirements may cause users to encounter additional authentication prompts during legitimate sign-ins.

    To help me narrow down the cause, could you please confirm:

    Are employees receiving these codes via SMS, email, or Microsoft Authenticator?

    • Did all affected employees start receiving them at approximately the same time?

    Were there any recent changes to Conditional Access, MFA, or Passkey/FIDO2 policies?

    If possible, please also share a sample sign-in log entry from an affected user, with personal information removed.

    I hope this helps you identify whether the behavior is related to a configuration change, a Microsoft service issue, or unexpected sign-in activity.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.