Skip to content

How Microsoft Authenticator’s scores are calculated

The full audit trail, recomputed from the verdict data at build time through the same code that produced the leaderboard: verdict × quality × story weight per cell, cells sum to dimension scores, dimensions blend into the PA Score. Every number on the product page is reproducible from this page alone; for why the formula looks like this, see the methodology.

verdict factors: full ×1.0 · partial ×0.6 · disputed ×0.3 · none ×0.0 · n/a excluded from both sides · cell points = weight × quality × factor · cell max = weight × 10

PA Score1/100

Agent-ready 0.0 × 0.30 = 0.00

API quality 0.0 × 0.20 = 0.00

Openness 5.4 × 0.20 = 1.08

Built-in AI 0.0 × 0.15 = 0.00

Automation 0.0 × 0.15 = 0.00

(0.00 + 0.00 + 1.08 + 0.00 + 0.00) ÷ (0.30 + 0.20 + 0.20 + 0.15 + 0.15) = 1.08 ÷ 1.00 = 1.1

Scores are stored to 1 decimal; the product page’s pills round to whole numbers for display. Each dimension below shows the stories, verdicts, and cited evidence behind its number.

Agent-ready0.0/100×0.30 of the PA blend

Outside-in: can YOUR agent reach and drive this product — API, MCP, CLI, headless runs, agent docs.

Point an agent at llms.txt or agent-oriented docsweight 2

2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max

  • [probe] https://support.microsoft.com/llms.txtPROBE llms.txt: HTTP 404 at https://support.microsoft.com/llms.txt
  • [probe] https://support.microsoft.com/en-us/authenticator/microsoft-authenticator-faqs.mdPROBE docs-md: HTTP 404 at https://support.microsoft.com/en-us/authenticator/microsoft-authenticator-faqs.md
  • [probe] https://support.microsoft.com/openapi.jsonPROBE openapi: all candidate paths 404 (https://support.microsoft.com/openapi.json, https://support.microsoft.com/swagger.json, https://support.microsoft.com/api/openapi.json, https://support.microsoft.com/.well-known/openapi.json)

Run the product headlessly / in CI for automationweight 2

2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

Plug MCP servers into this product so it can use their toolsweight 3

n/a — not applicable to this product: excluded from numerator and denominator

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

Connect an agent via an official MCP serverweight 3

3 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 30 max

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

Use an official CLIweight 2

2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

Drive the product through a documented public APIweight 3

3 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 30 max

  • [probe] https://support.microsoft.com/llms.txtPROBE llms.txt: HTTP 404 at https://support.microsoft.com/llms.txt
  • [probe] https://support.microsoft.com/en-us/authenticator/microsoft-authenticator-faqs.mdPROBE docs-md: HTTP 404 at https://support.microsoft.com/en-us/authenticator/microsoft-authenticator-faqs.md
  • [probe] https://support.microsoft.com/openapi.jsonPROBE openapi: all candidate paths 404 (https://support.microsoft.com/openapi.json, https://support.microsoft.com/swagger.json, https://support.microsoft.com/api/openapi.json, https://support.microsoft.com/.well-known/openapi.json)

Issue scoped/least-privilege API credentials for an agentweight 2

2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

Build against official SDKsweight 2

2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

Subscribe to events via webhooksweight 2

n/a — not applicable to this product: excluded from numerator and denominator

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

Agent-ready = 0.0 ÷ 160 × 100 = 0.0

API quality0.0/100×0.20 of the PA blend

The programmable surface once an agent is there — machine-readable spec, interactive docs, sandbox, versioning discipline.

Explore an interactive API reference with runnable examplesweight 2

n/a — not applicable to this product: excluded from numerator and denominator

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

Download a machine-readable API spec (OpenAPI or equivalent)weight 2

2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max

  • [probe] https://support.microsoft.com/llms.txtPROBE llms.txt: HTTP 404 at https://support.microsoft.com/llms.txt
  • [probe] https://support.microsoft.com/en-us/authenticator/microsoft-authenticator-faqs.mdPROBE docs-md: HTTP 404 at https://support.microsoft.com/en-us/authenticator/microsoft-authenticator-faqs.md
  • [probe] https://support.microsoft.com/openapi.jsonPROBE openapi: all candidate paths 404 (https://support.microsoft.com/openapi.json, https://support.microsoft.com/swagger.json, https://support.microsoft.com/api/openapi.json, https://support.microsoft.com/.well-known/openapi.json)

Test against a sandbox environment without touching production dataweight 1

n/a — not applicable to this product: excluded from numerator and denominator

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

Rely on versioned APIs with a documented deprecation policyweight 2

2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

API quality = 0.0 ÷ 40 × 100 = 0.0

Openness5.4/100×0.20 of the PA blend

Can you leave, inspect, or self-host — data export, open source, portability.

Do everything through the API that I can do in the UIweight 2

2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max

  • [probe] https://support.microsoft.com/llms.txtPROBE llms.txt: HTTP 404 at https://support.microsoft.com/llms.txt
  • [probe] https://support.microsoft.com/en-us/authenticator/microsoft-authenticator-faqs.mdPROBE docs-md: HTTP 404 at https://support.microsoft.com/en-us/authenticator/microsoft-authenticator-faqs.md
  • [probe] https://support.microsoft.com/openapi.jsonPROBE openapi: all candidate paths 404 (https://support.microsoft.com/openapi.json, https://support.microsoft.com/swagger.json, https://support.microsoft.com/api/openapi.json, https://support.microsoft.com/.well-known/openapi.json)

Export all of my data in open formats and leaveweight 3

3 (weight) × 3 (quality) × 0.6 (partial) = 5.4 of 30 max

  • [claimed-docs] https://support.microsoft.com/en-us/authenticator/export-passwords-from-microsoft-authenticatorScroll down to the Autofill section and select Export Passwords.
  • [claimed-docs] https://support.microsoft.com/en-us/authenticator/back-up-your-accounts-in-microsoft-authenticatorTurn on the Cloud Backup toggle. Select a Microsoft personal account where the backup will be stored.
  • [claimed-docs] https://support.microsoft.com/en-us/authenticator/export-passwords-from-microsoft-authenticatorScroll down to the Autofill section and select Export Passwords... Import your passwords.
  • [community] https://news.ycombinator.com/item?id=41275846Even for Microsoft accounts, use an alternative app for 2FA/MFA. Recently I switched to the open source Aegis, which allows encrypted backups and does not have the issue described.
  • [community] https://news.ycombinator.com/item?id=41275846people pick MS Authenticator - it's because microsoft basically forces it on you, uses dark patterns to avoid letting you use any other standard OTP app and doesn't give admins the tools to disable it... The QR code they get is not a standard TOTP one, so any other client will reject it.

Read the product's source under an open licenseweight 2

2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max

  • [probe] https://support.microsoft.com/llms.txtPROBE llms.txt: HTTP 404 at https://support.microsoft.com/llms.txt
  • [probe] https://support.microsoft.com/en-us/authenticator/microsoft-authenticator-faqs.mdPROBE docs-md: HTTP 404 at https://support.microsoft.com/en-us/authenticator/microsoft-authenticator-faqs.md
  • [probe] https://support.microsoft.com/openapi.jsonPROBE openapi: all candidate paths 404 (https://support.microsoft.com/openapi.json, https://support.microsoft.com/swagger.json, https://support.microsoft.com/api/openapi.json, https://support.microsoft.com/.well-known/openapi.json)

Self-host the core productweight 3

3 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 30 max

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

Openness = 5.4 ÷ 100 × 100 = 5.4

Built-in AI0.0/100×0.15 of the PA blend

Inside-out: how agentic the product itself is for its users — built-in assistants, autonomous features.

Get AI-generated insights and suggestions from my data inside the productweight 2

n/a — not applicable to this product: excluded from numerator and denominator

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

Set up automations that run autonomously in the backgroundweight 2

2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

Delegate tasks to a built-in AI assistant inside the productweight 3

n/a — not applicable to this product: excluded from numerator and denominator

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

Operate the product with natural-language commandsweight 2

2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

Built-in AI = 0.0 ÷ 40 × 100 = 0.0

Automation0.0/100×0.15 of the PA blend

Depth of automation primitives — rules, scheduling, bulk operations, webhooks.

Perform bulk operations across many items at onceweight 2

2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

Define rules that trigger actions automatically on eventsweight 3

n/a — not applicable to this product: excluded from numerator and denominator

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

Schedule recurring jobs or workflowsweight 2

n/a — not applicable to this product: excluded from numerator and denominator

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

Version, review, and roll back my automationsweight 1

n/a — not applicable to this product: excluded from numerator and denominator

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

Automation = 0.0 ÷ 20 × 100 = 0.0