Point Wild describes Tycoon 2FA as a business model: Tycoon 2FA is a phishing-as-a-service selling MFA bypass to low-skill actors; it's cheap, scaling fast, and silently relays credentials, MFA approvals and sessions to an adversary in real time.
![]()
Point Wild describes Tycoon 2FA as a business model: Tycoon 2FA is a phishing-as-a-service selling MFA bypass to low-skill actors; it's cheap, scaling fast, and silently relays credentials, MFA approvals and sessions to an adversary in real time.
![]()

I wonder, how does this work on Edge/Windows, since you are never logged out? I do not have a passwordless login, yet I was never asked to enter a password, not on Windows, nor on android, MS authenticator took care of it, ONCE, after a clean install! Ever since, Windows uses passkey to login everywhere.
View attachment 295967
That is a public spam email.It's best to delete that part.![]()
I think they start you off with a phishing page, so they have control of the authentication flow. I also note:I wonder, how does this work on Edge/Windows,
MS passkey can not be disabled, I tried many times, since I do not like the idea of always being logged in without any verification at all, it is just multiple UAC prompts.
- Not everybody has signed on to use passkeys, despite Microsoft's and Google's push.
Microsoft Authenticator is one thing that MS did right, it is the only Authenticator that allows people to log into Windows directly without anything else.
- Microsoft Authenticator may fall into the same boat as the TOTP authenticator.
I personally found it convenient. I have some misgivings about revoking the authenticator's access, though. The last time I tried, changing the password and revoking all active sessions didn't revoke access to the authenticator, meaning you can still grant log-ins or 2FA approval despite the password change. You would have to do some obscurely-documented EXTRA thing to remove access.Microsoft Authenticator is one thing that MS did right
I am not sure if this is what you are looking for. The last time I managed to delete all passkeys for my Microsoft account, I went to the "Manage how I sign in" screen, deleted all the passkeys listed, and "Reset Windows Hello on all of my Windows devices". Of course, I don't know how MS will behave now.MS passkey can not be disabled
That screen looks like you are trying to delete the passkey from your Windows device, not your Microsoft account. With all the passkeys deleted from your Microsoft account and resetting the Windows Hello option, can you still log into your Microsoft account from an incognito browser?