Question about Microsoft Account Sign-in Verification


AshForeth

Active member
Member
Local time
4:39 PM
Posts
109
OS
Windows 11 24H2
Microsoft has been pushing passkey lately so I revisited my Microsoft Account. Based on the security settings, you can have

Sign-in Method - what you use to login
  • Password
  • Security Key or pin or biometrics
  • App - Microsoft Authenticator.
Veriify method or 2FA. N ote that MS does not allow security key authentication.
  • SMS - supposedly removed now for new users
  • Email
  • TOTP
  • Push notification
There is an additional setting for two step authentication, which is turned on for me. The two step is for 2FA.

My thought was to remove the SMS and the email, but Microsoft seems to post a warning against doing that in this link: "If you request removal of all security information in your account, the account is put into a restricted state for 30-days.". I poke around and it appears to mean if you remove your email and phone method. My guess is Microsoft is certain that if you remove your email and phone , they have no way to identify you. Frankly, I don't understand why they can't just make this a required field elsewhere and allow the user to not use it as a verification method. Currently, it appears that if I remove both method, my account may be restricted. I am not going to try to to find out. Has anyone actually tried removing both email and SMS? Note that SMS may have been removed for new accounts.

Microsoft does allow you to remove the password. While I did like that password can be removed, it could not be done because then I can't use the account to login into services like RDP to a server. As a result, I had to retain thee TOTP or the push notification. As mentioned before I still have to have SMS or email as a backup. What is the min method you are using to login to minimize attack surfaces?

Thanks
 

My Computers My Computers

  • At a glance

    Windows 11 24H2AMD Ryzen AI 9 HX 370 Processor 2.0GHz64 GbNVIDIA® GeForce RTX 4070 Laptop GPU
    OS
    Windows 11 24H2
    Computer type
    Laptop
    Manufacturer/Model
    ASUS ProArt P16
    CPU
    AMD Ryzen AI 9 HX 370 Processor 2.0GHz
    Motherboard
    N/A
    Memory
    64 Gb
    Graphics Card(s)
    NVIDIA® GeForce RTX 4070 Laptop GPU
    Sound Card
    N/A
    Monitor(s) Displays
    N/A
    Screen Resolution
    3840 x 2400
  • At a glance

    Windows 11 23H2AMD Ryzen 5 560032 GbAMD RX6600
    Operating System
    Windows 11 23H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Home Built
    CPU
    AMD Ryzen 5 5600
    Motherboard
    MSI MS-7C56
    Memory
    32 Gb
    Graphics card(s)
    AMD RX6600
I am not going to try to to find out. Has anyone actually tried removing both email and SMS? Note that SMS may have been removed for new accounts.
As far as I know you have to have an email associated with it, but I am no expert.

The experts should be here shortly to help.

Microsoft sign in is pretty crazy, some times it works and sometimes it does not.

I now use the pin (passkey) to sign in at works well.

I could never get the Microsoft Authenticator app to work after multiple reinstalls on Android phone.

But it works for other accounts I have, not Microsoft.

Very odd.

I have had to change my Microsoft password several times becuase microsoft sais my passwrd was not correct.

Don get me started on my Unraid mapped drives that took hours because Windows said my credentials were wrong.
 
Last edited:

My Computer My Computer

At a glance

Windows 11proIntel Core i7-14700K Raptor Lake-S Refresh 3....Crucial Pro 96GB (2 x 48GB) DDR5-5600 PC5-44800PNY NVIDIA GeForce RTX 5080 EPIC-X RGB Overcl...
OS
Windows 11pro
Computer type
PC/Desktop
Manufacturer/Model
Homebuilt
CPU
Intel Core i7-14700K Raptor Lake-S Refresh 3.4GHz
Motherboard
MSI Z790 MAG Tomahawk Max WiFi Intel LGA 1700 ATX Motherboard
Memory
Crucial Pro 96GB (2 x 48GB) DDR5-5600 PC5-44800
Graphics Card(s)
PNY NVIDIA GeForce RTX 5080 EPIC-X RGB Overclocked Triple Fan 16GB GDDR7
Sound Card
Onkyo AVR TX-NR656 5.1
Monitor(s) Displays
3X -LG 32GN650-B Ultragear Gaming Monitor 32” QHD (2560 x 1440) Display, 165Hz Refresh Rate
Screen Resolution
2560 x 1440)
Hard Drives
Wat to many.
PSU
Corsair RM1000e Fully Modular Low-Noise Power Supply - ATX 3.1 & PCIe 5.1
Case
Lian Li LANCOOL 207 DIGITAL Tempered Glass ATX Mid-Tower
Cooling
Thermaltake TH240
Keyboard
Corsair K95 RGB Platinum
Browser
Brave
Antivirus
Defender
Other Info
This is 1 of 5 HTPC also have built a PC for Blue Iris security software.
As far as I know you have to have an email associated with it, but I am no expert.

The experts should be here shortly to help.

Microsoft sign in is pretty crazy, some times it works and sometimes it does not.

I now use the pin (passkey) to sign in at works well.

I could never get the Microsoft Authenticator app to work after multiple reinstalls on Android phone.

But it works for other accounts I have, not Microsoft.

Very odd.

I have had to change my Microsoft password several times becuase microsoft sais my passwrd was not correct.

Don get me started on my Unraid mapped drives that took hours because Windows said my credentials were wrong.
Thanks in the past I did try to remove both years ago but Microsoft required that I have either an email or a phone.
 

My Computers My Computers

  • At a glance

    Windows 11 24H2AMD Ryzen AI 9 HX 370 Processor 2.0GHz64 GbNVIDIA® GeForce RTX 4070 Laptop GPU
    OS
    Windows 11 24H2
    Computer type
    Laptop
    Manufacturer/Model
    ASUS ProArt P16
    CPU
    AMD Ryzen AI 9 HX 370 Processor 2.0GHz
    Motherboard
    N/A
    Memory
    64 Gb
    Graphics Card(s)
    NVIDIA® GeForce RTX 4070 Laptop GPU
    Sound Card
    N/A
    Monitor(s) Displays
    N/A
    Screen Resolution
    3840 x 2400
  • At a glance

    Windows 11 23H2AMD Ryzen 5 560032 GbAMD RX6600
    Operating System
    Windows 11 23H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Home Built
    CPU
    AMD Ryzen 5 5600
    Motherboard
    MSI MS-7C56
    Memory
    32 Gb
    Graphics card(s)
    AMD RX6600
You can set up two passkeys (e.g. Windows and Android) plus a recovery code (stored offline) to eliminate everything else.
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
Computer type
Laptop
Well I answered my own question by trying this on a relatively unused account. The account used is passwordless (meaning you can only login using a passkey). The passkey are stored on 3 different Yubikeys, which should be redundant enough, but when I attempt to delete the email address verification method, I get a prompt saying that I must add another email ior it won't delete the email. I guess nothing has change over the past couple of years and the account still demand you add an email. The only difference is that you can no longer add a SMS fallback.
 

My Computers My Computers

  • At a glance

    Windows 11 24H2AMD Ryzen AI 9 HX 370 Processor 2.0GHz64 GbNVIDIA® GeForce RTX 4070 Laptop GPU
    OS
    Windows 11 24H2
    Computer type
    Laptop
    Manufacturer/Model
    ASUS ProArt P16
    CPU
    AMD Ryzen AI 9 HX 370 Processor 2.0GHz
    Motherboard
    N/A
    Memory
    64 Gb
    Graphics Card(s)
    NVIDIA® GeForce RTX 4070 Laptop GPU
    Sound Card
    N/A
    Monitor(s) Displays
    N/A
    Screen Resolution
    3840 x 2400
  • At a glance

    Windows 11 23H2AMD Ryzen 5 560032 GbAMD RX6600
    Operating System
    Windows 11 23H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Home Built
    CPU
    AMD Ryzen 5 5600
    Motherboard
    MSI MS-7C56
    Memory
    32 Gb
    Graphics card(s)
    AMD RX6600
Back
Top Bottom