I'm receiving login attempts to my account that I didn't initiate.

Muhammad Alhammami 0 Reputation points
2026-05-24T06:08:05.1633333+00:00

Hello

I'm receiving many login attempts to my account that I didn't authorize, and I'm denying them using the Authenticator app.

I'm worried about hacking and theft of my account.

How can you help me protect my account and myself?

Microsoft Security | Microsoft Entra | Microsoft Entra Private Access

2 answers

Sort by: Most helpful
  1. Shubham Sharma 17,925 Reputation points Microsoft External Staff Moderator
    2026-05-25T02:01:31.17+00:00

    Hi Muhammad Alhammami,

    Thank you for reaching out to Microsoft Q&A.

    I'm sorry to hear that you're experiencing unauthorized login attempts. Protecting your account is crucial. Here are steps you can take to secure your Microsoft account:

    1. Change Your Password Immediately

    2. Ensure Multi-Factor Authentication (MFA) is Enabled

    • You're already using the Microsoft Authenticator app, which is great.
    • Make sure MFA is enforced on all your sign-ins. Review your Security Info to confirm.

    3. Review Recent Activity

    • Visit the Recent Activity page to check for any suspicious sign-in attempts.
    • If you see any activity you don't recognize, follow the prompts to secure your account.

    4. Remove Unrecognized Devices

    • Go to Devices and remove any devices you don't recognize.

    5. Update Security Information

    • Ensure your recovery email and phone number are up to date at the Security Info page.

    6. Report Suspicious Activity

    7. Be Aware of Phishing Attempts

    • Never approve sign-in requests you did not initiate.
    • Be cautious of emails or messages asking for your credentials.

    References:

    Was this answer helpful?

    0 comments No comments

  2. AI answer

    2026-05-24T06:08:21.9766667+00:00

    Those unrequested prompts mean someone or something is repeatedly trying to sign in with the account. Denying the prompts is the right action; now add more protection and review activity.

    1. Do not approve any unrequested prompts or codes
    • In the Authenticator or Outlook mobile prompt, always select Deny if the sign-in was not initiated.
    • For verification codes received by SMS/email that were not requested, do not enter or reply to them. Without the correct response, the attacker cannot complete sign-in.
    1. Review recent sign-in activity
    • Go to the Security basics page and open Review activity / Recent activity.
    • Look for:
      • Unusual locations, devices, or apps.
      • Multiple unsuccessful sign-ins.
    • For any activity that is not recognized:
      • If it appears under Unusual activity, expand it and select This wasn’t me.
      • If it appears under Recent activity, expand it and select Secure your account.
    1. Change the password and enable/strengthen MFA
    • From the Security basics page, select Change password and set a strong, unique password.
    • Ensure multi-factor authentication (two-step verification) is enabled and working:
      • Register the Microsoft Authenticator app as a primary method.
      • Add at least one backup method (SMS, email, or security key) on the Security info page if available for the work/school account.
    • If sign-in logs show “Additional verification failed, invalid code,” it may mean the attacker has the password but is blocked by MFA. In that case, change the password immediately and verify all MFA methods.
    1. Consider going passwordless
    • For Microsoft accounts, turn on Passwordless account:
      • Sign in to Additional security options and under Passwordless account, select Turn on.
      • Approve the request in Microsoft Authenticator.
    • Passwordless methods (Authenticator, Windows Hello, security keys, SMS codes) are more resistant to guessing and phishing than passwords.
    1. Monitor and search sign-in logs
    • For work or school accounts, use My sign-ins:
      • Search for Unsuccessful sign-ins to see repeated attempts.
      • Confirm any unusual activity directly in the My sign-ins page.
    • On Android, open Microsoft Authenticator → work/school account → Recent account activity and review each sign-in. If anything is unfamiliar, change the password again.
    1. If sign-in attempts are very frequent or suspicious
    • Treat this as a potential attack:
      • Ensure all devices used to access the account are secure (updated OS, antivirus, no unknown apps).
      • If unable to sign in after multiple attempts or suspect malicious activity, contact the organization’s IT administrator so they can review Microsoft Entra sign-in logs and adjust MFA or conditional access policies.

    Following these steps ensures that even if someone has the password, they cannot access the account, and any ongoing attack attempts can be detected and contained.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.