Unusual Account Activity from MS IP Addresses

Anonymous
2022-07-15T04:15:50+00:00

Yesterday I received an email from your Microsoft Account Team regarding unusual activity.  When I looked into it, it showed an unusual actvity detected for an Automatic POP3 sync from IP 13.101.248.75.  This activity did not have my account alias listed as it usually does, and listed the location as United States.  On the review activity page I said this was not me.  I changed my password, but then saw another unusual account activity from IP 13.101.248.41. This one did have my account alias listed.   I changed my passwords almost 1/2 dozen times yesterday.24hrs after my final password change, I received today another email regarding unusual activity.  It was another unusual activity detected for an Automatic POP3 sync from IP 13.101.248.75. Once again I confirmed this was not me, although this time I did not change my password.  Three hours later, I received yet another notification of unusual activity.  This time it was for IP 13.101.219.207  However, at the same time it had the exact same thing for IP address 13.101.53.212.  While I was not notified of that one, nor asked to confirm if this was me, it does list it as unusual activity. I looked all the IP address up on ARIN WHOIS.  According to them they all belong to Microsoft. I am sending this to all the email addresses on ARIN WHOIS that are listed as a point of contact.  I NEED ANSWERS. This has never happened before yesterday. I am afraid to confirm that these are me because I don't understand why MS IPs would be POP3 syncing to my account. I only have my Gmail account to POP3 sync to this email.  Those IP addresses tend to begin with a 2607 number.  I keep saying this isn't me, but not sure what I should do. Ignore, confirm it's me or continue to say it's not me. I want to know why is a Microsoft IP auto syncing to my email account? So much so that it generates an unusual activity text/email?I NEED some guidance on this.  There is no help article covering this.  And there is no way to contact a live person for help, which is ABSOLUTELY RIDICULOUS!

Outlook | Windows | Classic Outlook for Windows | For business

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2022-07-19T21:48:24+00:00

Finally got to talk to someone at MS- this was their reply:

Thank you for the information. Please be advise that Microsoft is aware of this known issue already. This started to happen even last week and we are already working with this matter. We even have created a ticket number for this issue while it is still happening.

The ticket number for the emerging issue is INC31680156.

So they are on it, but no idea when it will be fixed.

[EDIT] They also confirmed that the account was secure, no need to change passwords, etc

Was this answer helpful?

30+ people found this answer helpful.
0 comments No comments

52 additional answers

Sort by: Most helpful
  1. Anonymous
    2022-07-18T01:02:30+00:00

    Same issue here, IMAP syncs from Microsoft (13.101.148.105) for the last four days. Getting really annoying!

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2022-07-17T18:20:52+00:00

    Been getting these for about a week in a row, someone please look into this. Please no generic "secure your account" "just for kudos" posts please. I feel that their DNS is failing to see these IPs as whitelisted, or someone messed up and forgot to add them, and this needs to be addressed. FWIW pop3 is disabled on all my accounts,

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2022-07-16T18:54:56+00:00

    Hello,

    I also have this issue. I have received the first e-mail on July 15th 2022, 17:19 UTC.

    The IP addresses in question are:

    • 13.101.111.171
    • 13.101.111.74
    • 13.101.111.133

    I don't use this Microsoft account for anything important (well, except for a Windows 11 license I recently bought) - I even don't really use it for e-mail. I only have my Thunderbird on Linux check this account periodically so that it does not expire (and get removed) because of inactivity (or so this was the idea - I don't know if MS accounts expire in this way).

    I think that this is just a false alarm and some internal Microsoft services are acting as a proxy and triggering a warning. If there was some malicious activity going on, the attackers would probably use SMTP to send spam, but there was no SMTP access.

    I can't completely exclude that some Azure "customers" are breaking into Microsoft accounts, though - but this seems less likely.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2022-07-16T16:32:15+00:00

    I'm having the same issue, started July 15th.

    Type: Unusual activity detected

    Protocol: POP3 IP: 13.101.75.41 Account alias: (my email)

    When I look up the IP, it says Organization: Microsoft Corporation (MSFT)

    Was this answer helpful?

    0 comments No comments