Why Microsoft Authenticator ditched multiple-choice logins

Microsoft Authenticator is rolling out a security update that replaces its multiple-choice login verification with manual number entry. Instead of tapping one of three displayed options to approve a login attempt, users will now be required to type a specific number manually. This change is currently rolling out across both enterprise/education accounts and personal Microsoft accounts.

While the shift from multiple-choice to manual entry reduces guessing odds by 67%, the primary motivation is security-focused. By requiring manual input instead of simple tapping, Microsoft aims to significantly reduce accidental approvals and protect against spam attacks where malicious actors attempt to trigger unwanted authentication approvals. The previous multiple-choice interface inadvertently made it easier for both accidental approvals and mass-attack scenarios.

This update represents Microsoft’s continued effort to strengthen authentication security across its ecosystem. The rollout to personal accounts indicates this is becoming a standard security practice, not just an enterprise-level feature, as Microsoft prioritizes reducing friction from false approval attempts and defending against coordinated attack patterns.

Sources