Good guy, Microsoft: Multi-factor auth outage gives cloudy Office, Azure users a surprise three-day weekend


TOTP authentication does not work by the site "sending" a code anywhere. The code is synthesised on the device (user's phone) from the current time and an initial value set when the authentication was set up. I don't know whether Microsoft's authenticator app also offers some other mechanism, but I use Google's Authenticator app for my Micorosft 2FA, so they do support standard TOTP.

The linked Microsoft announcement says "Users may not receive authentication requests via phone call, SMS or within their authenticator app." Perhaps they meant something internal to their infrastructure was not receiving requests. Or perhaps they meant to write "replies", as The Register assumed, and it is wrong about TOTP access being disrupted.

