|
|
|
|
|
by bayindirh
484 days ago
|
|
Two reasons: 1. You shouldn't be reusing your password anywhere else anyway. 2. Microsoft corporate 2FA doesn't give you three choices, but wants you to enter the number from your keypad, unlike consumer 2FA, preventing flooding attacks and trusting that you'll tap the right one accidentally. |
|
2. Yes, I know how the MS 2FA flow works. But why doesn't it have you enter number on device first, type password second? Seems like it would give users a better way of knowing the login request is legit?