I've had "automatic sync" show up in my "Recent Activity" numerous times - a couple of weeks later (seriously!) I've gotten a notification of "We think that someone else might have accessed (insert-mail
address here)..."
At which point I'm forced to change my password. Again.
MS never actually tell me why they think someone else has accessed my account, and "Recent Activity" never shows any suspicious events within the preceding 24 hours or so.
I have two-stage authorisation set up, and am using Authenticator. Just checked "Recent Activity", and there are four more attempts at Automatic Sync in the last few hours - three from Brazil, one from Malaysia. As I'm a resident of neither, you'd think
Microsoft would automatically block them. Not so...
It gets worse! Here's the Recent Activity showing the four attempts as being "unsuccessful":

BUT... if I click on "Secure your account", the exact same events suddenly change to "successful":

What on earth is going on?
I'll confess that my Internet knowledge is scant and there may be reasons why not, but I'm an Australian living in Australia - literally ALL my legit account activity is from IP's based in Australia. If Microsoft detects an attempt to access my account from,
y'know, the other side of the world, why would they allow it to proceed?
If ALL my account activity is from, say, Sydney, then someone tries to login / automatically sync from Brazil, why wouldn't they
automatically flag that as suspicious, and block it?
Makes no sense to me...
Hi there!
Thank you for your inquiry.
I am pleased to inform you that the change from "unsuccessful sync" to "successful sync" after you clicking
Secure your account is just a visual bug. The hacker cannot log in to your account if you have
two-step verification enabled.
If you do not have two-step verification enabled, Microsoft security algorithms will proactively block login attempts with unrecognised devices from unfamiliar locations/networks. This is when the
Recent activity page truly matters.
Otherwise, you do not have to monitor your Recent Activity page because the hacker would need very sophisticated resources/equipment to hack accounts with 2-Factor Authentication in place… usually for targeted state-sponsored attacks.
Cheers!
— XP