


Having a second factor – typically a text message sent to your phone or, better still, a random six digit number created by an Authenticator application on your mobile means that even if your password is compromised and someone finds out what it is they can’t login without the random six digit number.If you are an Admin User who wish to create App Passwords so that you can use them in your code/web applications so that you don’t have to store credentials in your application? Example: Azure Function you are developing shouldn’t store the password of the User.Īt times, you must’ve noticed that why you can’t create App Passwords even when you are having MFA enabled for yourself!

If you’d like to find out where YOUR email address has been compromised then you can look this up against a database of known breaches at In short, keeping your password safe and secure is a lot more problematic than you might otherwise think. In addition to these breaches, there is an entire industry of criminal gangs, phishing for your email password so that they can use this to assume your identity and commit fraud. In addition to these known numbers, there will have been many more unpublished or unknown breaches. Over the years, there have been countless published breaches of high profile websites where literally billions of emails and passwords have been compromised.
