Providing secure, identity-based access to private apps and resources without traditional VPNs
Those unrequested prompts mean someone or something is repeatedly trying to sign in with the account. Denying the prompts is the right action; now add more protection and review activity.
- Do not approve any unrequested prompts or codes
- In the Authenticator or Outlook mobile prompt, always select Deny if the sign-in was not initiated.
- For verification codes received by SMS/email that were not requested, do not enter or reply to them. Without the correct response, the attacker cannot complete sign-in.
- Review recent sign-in activity
- Go to the Security basics page and open Review activity / Recent activity.
- Look for:
- Unusual locations, devices, or apps.
- Multiple unsuccessful sign-ins.
- For any activity that is not recognized:
- If it appears under Unusual activity, expand it and select This wasn’t me.
- If it appears under Recent activity, expand it and select Secure your account.
- Change the password and enable/strengthen MFA
- From the Security basics page, select Change password and set a strong, unique password.
- Ensure multi-factor authentication (two-step verification) is enabled and working:
- Register the Microsoft Authenticator app as a primary method.
- Add at least one backup method (SMS, email, or security key) on the Security info page if available for the work/school account.
- If sign-in logs show “Additional verification failed, invalid code,” it may mean the attacker has the password but is blocked by MFA. In that case, change the password immediately and verify all MFA methods.
- Consider going passwordless
- For Microsoft accounts, turn on Passwordless account:
- Sign in to Additional security options and under Passwordless account, select Turn on.
- Approve the request in Microsoft Authenticator.
- Passwordless methods (Authenticator, Windows Hello, security keys, SMS codes) are more resistant to guessing and phishing than passwords.
- Monitor and search sign-in logs
- For work or school accounts, use My sign-ins:
- Search for Unsuccessful sign-ins to see repeated attempts.
- Confirm any unusual activity directly in the My sign-ins page.
- On Android, open Microsoft Authenticator → work/school account → Recent account activity and review each sign-in. If anything is unfamiliar, change the password again.
- If sign-in attempts are very frequent or suspicious
- Treat this as a potential attack:
- Ensure all devices used to access the account are secure (updated OS, antivirus, no unknown apps).
- If unable to sign in after multiple attempts or suspect malicious activity, contact the organization’s IT administrator so they can review Microsoft Entra sign-in logs and adjust MFA or conditional access policies.
Following these steps ensures that even if someone has the password, they cannot access the account, and any ongoing attack attempts can be detected and contained.
References:
- Using Outlook mobile to sign in
- Common problems with two-step verification for a work or school account
- View your work or school account sign-in activity from My Sign-ins
- What happens if there's an unusual sign-in to your account
- What is the Recent activity page?
- How to help keep your Microsoft account secure