Forum Discussion
Microsoft Account 2FA Email Wording
Previously, logging into microsoft accounts via email 2FA would send an email to the recovery inbox worded roughly:
Security Code
Please use the following security code for your personal account mailto:email address removed for privacy reasons
Security code: xxxxxx
Recently, the wording has shifted into:
Hi mailto:email address removed for privacy reasons
We received your request for a single-use code to use with your Microsoft account.
Your single-use code is: xxxxxx
2FA emails seem to no longer state the account linked to your recovery email that issued the code.
This ambiguous wording makes phishing and social engineering attacks easier.
I suggest revert back to using the original emailing 2FA format, or at least stating the account in the email.