Feb 24 2023 01:18 AM
Allows users to report suspicious activities if they receive an authentication request that they did not initiate. This control is available when using the Microsoft Authenticator app and voice calls. Reporting suspicious activity will set the user's risk to high. If the user is subject to risk-based Conditional Access policies, they may be blocked.
Mar 09 2023 09:08 AM
Mar 09 2023 10:55 AM
May 11 2023 09:36 PM
Jun 19 2023 12:34 AM - edited Jun 19 2023 12:35 AM
@eliekarkafy Please can you confirm what Reporting Code refers to? It's not mentioned on the guidance article.
Jun 19 2023 02:59 AM
@Anthony Cotton Hi, there is no explanation till now for the reporting code usage in any MS documentation. I used to change the reporting code during my initial testing for that feature and couldn't notice any changes on the level of the user experience or in the user detection logs on Azure.
it might be a parameter for the feature, or it might be something for future use.
Aug 04 2023 07:10 AM
Aug 09 2024 09:02 AM - edited Aug 09 2024 09:07 AM
@eliekarkafy We recently saw a Message Center notification informing us that MFA Fraud Alert would be replaced by the new Report Suspicious Activity settings (as shown in your screenshot) in March 2025.
One concern we have about this change is that the new Report Suspicious Activity settings will automatically set the user's risk to high when they report the activity. The new settings do not allow an organization to choose whether the user's risk is updated to high or remains unchanged.
Due to the high number of accidental and false positive reports, we do not currently automatically block users who report fraud or require them to change their passwords based upon a fraud/suspicious activity submission. We do this only after our internal security team has investigated the report and confirmed the situation with the user.
My request is that Microsoft consider adding an opt-in/out option for automatically assigning high risk to users who reports suspicious activity. If we are unable to opt-out of automatically setting a user's risk to high upon reporting suspicious activity, then we have to consider disabling the new settings when they replace the MFA Fraud Alert settings in March avoid additional password resets due to a user's accidental or uninformed suspicious activity submission.