Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Oasis Security described a historical weakness in Microsoft’s multi-factor authentication (MFA) flow: someone with a valid account password could repeatedly guess the six-digit authenticator code by starting fresh sign-in sessions. The researchers said failed guesses did not alert account owners. Oasis’s timeline says Microsoft deployed a permanent fix on October 9, 2024, so this is a resolved historical issue—not a claim of a currently unpatched Azure vulnerability.

What was the Microsoft MFA flaw?

In its report, Oasis Security said Microsoft’s sign-in flow allowed up to 10 consecutive incorrect authenticator-code attempts in one session. An attacker who already had a valid email address and password could start additional sessions and continue guessing rather than being stopped by a meaningful limit across those sessions.

The weakness was in the second-factor verification and its rate limiting, not a way to bypass the password step. Oasis also reported that the failed attempts in its described scenario did not trigger account-owner alerts, reducing the chance that the legitimate user would notice the guessing.

The report covered Microsoft account sign-ins and services including Outlook, OneDrive, Teams, and Azure Cloud. It does not establish a flaw isolated to Azure infrastructure.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Could attackers bypass Microsoft MFA without a password?

No. The attack Oasis described required valid account credentials, including the password. The researchers demonstrated repeated attempts to guess the second-factor code after the password had been accepted; they did not describe a password-free takeover.

Oasis reported successful researcher demonstrations, but the cited account does not establish criminal exploitation in the wild or prove that any users were compromised. Microsoft’s more than 400 million paid Office 365 seats, announced by CEO Satya Nadella on January 30, 2024, indicate the scale of the service—not the number of accounts affected or attacked.

Rank #2
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

How did the code guessing work?

The flow used a six-digit authenticator code. Oasis said one session permitted up to 10 consecutive failed entries; by creating fresh sessions, researchers could continue making guesses. The practical concern was the combination of session-by-session attempts and the time for which a code remained acceptable.

Oasis said its testing found Microsoft sign-in tolerated a time-based code for around three minutes—about 2.5 minutes beyond its stated expiry. That is an observation from the researchers’ Microsoft sign-in testing, not a general property of authenticator apps or all time-based one-time password (TOTP) systems.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

The distinction matters: IETF RFC 6238 specifies a default TOTP time step of 30 seconds, but a time step is not a guarantee that every validator accepts a code for exactly 30 seconds. The specification allows validators to account for transmission delay and warns that accepting a wider window increases the attack window. Read RFC 6238.

When did Microsoft fix the flaw?

Date Event reported by Oasis Security
June 24, 2024 Microsoft acknowledged the issue.
July 4, 2024 Microsoft deployed a temporary fix.
October 9, 2024 Microsoft deployed a permanent fix.

Oasis published its report on December 11, 2024, and updated it on May 1, 2026. The researchers say the issue had been fixed before publication. Oasis has not disclosed the specific technical changes. It says Microsoft introduced a stricter rate limit after a number of failed attempts, with that strict limit lasting around half a day; the report does not provide further implementation details. Read Oasis Security’s report and timeline.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

What should Microsoft 365 and Entra administrators do?

Oasis’s recommendations are useful as general account-protection practices. They are not evidence that a particular tenant was attacked or compromised.

  • Enable MFA. Do not treat this historical flaw as a reason to disable a second factor.
  • Review failed second-factor sign-ins. Where your logging and monitoring support it, look for repeated failed MFA attempts and alert on patterns that merit investigation.
  • Make alerts actionable. Consider notifying affected account owners about suspicious or repeated failed second-factor attempts, so they can report activity they did not initiate.
  • Assess passwordless options. Stronger passwordless methods can reduce exposure to manually entered, short-lived codes and phishing, depending on the configured sign-in policy and devices. Check Microsoft’s current Microsoft Entra authentication-method guidance for methods and policy considerations.
  • Plan recovery before changing methods. Check user-device support, account recovery, and help-desk procedures alongside compatibility with the organization’s Entra policies. A physical security key is a possible passwordless method, not a fix for the historical server-side rate-limit weakness; verify that the organization’s policies support a particular model before buying it.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the incident does—and does not—show

The report describes a weakness that could make second-factor code guessing more practical for someone who already knew a valid password, compounded by missing alerts in the tested scenario. It does not show that a password was unnecessary, quantify compromised accounts, or establish criminal exploitation. Oasis’s published timeline says Microsoft’s permanent fix was deployed on October 9, 2024; the technical details remain undisclosed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified (Pack of 2)
  • The information below is per-pack only
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.