The next time you open the Microsoft Authenticator app to sign in to a device, you may encounter a new interface. Microsoft is introducing a change that requires you to manually enter the number instead of tapping one of the three options.
The update initially appeared for enterprise and education users, but has since been rolled out to personal Microsoft accounts. We have seen a new request appear on the personal device, indicating that the submission is in progress.
At first glance, you might think that this change makes Microsoft Authenticator 33 times more secure. This would be true if malicious actors hack accounts by guessing the number that appears.
Before the change, there were only three options, giving a theoretical blind hacker about a 33 percent chance of guessing. By requiring manual entry of a two-digit number, there is only a 1 percent chance of guessing it correctly.
But attacks based on multifactor authentication are usually not guessing games. Bad actors often spam users with a bunch of requests to authenticate, hoping the user will confirm the request or guess the correct number.
Random confirmations are also a problem. Since only three numbers appear on the screen, you may accidentally tap the correct number while opening the app or moving the phone in your pocket.
Requiring manual entry of the number greatly reduces these risks.
Microsoft has made several changes to its authenticator software to improve security. SMS codes are deprecated as an option for personal Microsoft accounts because they are not secure. SMS-based authentication is a leading source of fraud, Microsoft explains.
The change to requiring manual entry of numbers is more accurate than moving away from SMS-based authentication, but it adds another layer of security.
The update is rolling out gradually, so you may not see it yet.
Join us Reddit at r/WindowsCentral to share your thoughts and discuss our latest news, reviews and more.





