Using classic Outlook for Windows in business environments
I have changed my password , added 2 step security and it is still happening. The activity originates in Redmond Washington US with similar VP addresses and at similar times of day
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
I could not find a more direct forum than Outlook to ask this question, if it is not the right forum my apologies.
I received an e-mail alert that indicated unusual activity detected on my live.com account. When I checked the recent activity, I found two IP numbers. One matched my external IP and the other did not. I changed my password right away and checked the activity again. To my surprise, the other IP and its variants were appearing along with my external IP number at the same intervals.
I tried to find the IP number roots and ironically, it pointed at Microsoft. I am really confused! Can someone explain the source of this IP and whether I need to do anything to stop it from occurring.? I use Edge browser and I log in with my account. When it syncs, does it use a separate IP from my IP number?
Thank you,
Cemal
Note: I am not using the Outlook mail client. I check my mail using two different mail clients on two different computers at the same location that share the same external IP number. On occasion, I check my live.com e-mail online using a Web browser.
Using classic Outlook for Windows in business environments
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
I have changed my password , added 2 step security and it is still happening. The activity originates in Redmond Washington US with similar VP addresses and at similar times of day
Thanks, I'll wait.
In the meantime I looked at the timestamps of "unusual activity" and my own accesses and they seem to be somewhat related, but not completely in sync.
For yesterday I see:
| Activity from account.live.com | my own accesses |
|---|---|
| (no record) | July 17, 2022 11:51:40 PM EDT |
| (no record) | July 17, 2022 11:41:35 PM EDT |
| (no record) | July 17, 2022 11:31:31 PM EDT |
| (no record) | July 17, 2022 11:21:27 PM EDT |
| Protocol: POP3<br><br>Time: Yesterday 11:11 PMType: Successful sync | July 17, 2022 11:11:22 PM EDT |
| (no record) | July 17, 2022 11:01:16 PM EDT |
| Protocol: POP3<br>IP: 13.*********.102<br>Time: Yesterday 10:51 PM<br><br>Type: Unusual activity detected<br><br><br><br>Protocol: POP3<br>IP: 13.*******.39<br>Time: Yesterday 10:51 PMType: Unusual activity detected | July 17, 2022 10:51:12 PM EDT |
| (no record) | July 17, 2022 10:41:07 PM EDT |
| Protocol: POP3<br>IP: 13.*******.102<br>Time: Yesterday 10:31 PMType: Unusual activity detected<br><br><br><br>Protocol: POP3<br>IP: 13.*******.39<br>Time: Yesterday 10:31 PMType: Unusual activity detected | July 17, 2022 10:31:02 PM EDT |
| (no record) | July 17, 2022 10:20:57 PM EDT |
| Protocol: POP3<br>IP: 13.*******.84<br>Time: Yesterday 10:10 PMType: Unusual activity detected | July 17, 2022 10:10:52 PM EDT |
| (no record) | July 17, 2022 10:00:46 PM EDT |
| (no record) | July 17, 2022 09:50:42 PM EDT |
| (no record) | July 17, 2022 09:40:38 PM EDT |
| Protocol: POP3<br>IP: 13.********.102<br>Time: Yesterday 9:30 PMType: Unusual activity detected<br><br><br><br>Protocol: POP3<br>IP: 13.*******.39<br>Time: Yesterday 9:30 PMType: Unusual activity detected | July 17, 2022 09:30:33 PM EDT |
| (no record) | July 17, 2022 09:20:28 PM EDT |
| (no record) | July 17, 2022 09:10:23 PM EDT |
| Protocol: POP3<br>IP: 13.*******.102<br>Time: Yesterday 9:00 PMType: Unusual activity detected<br><br><br><br>Protocol: POP3<br>IP: 13.******.39<br>Time: Yesterday 9:00 PMType: Unusual activity detected | July 17, 2022 09:00:17 PM EDT |
| Protocol: POP3<br>IP: 13.********.210<br>Time: Yesterday 8:50 PMType: Unusual activity detected | July 17, 2022 08:50:12 PM EDT |
| (no record) | July 17, 2022 08:40:05 PM EDT |
| (no record) | July 17, 2022 08:30:01 PM EDT |
Etc.
So, the way I see it, for some random subset of my own accesses:
either
the access triggers some internal MSFT activity from their IP addresses that logs as "unusual activity"
or
a faulty log is generated .
I have seen at least 7 MSFT IP addresses in the logs.
13.***Remove PII***.102
13.***Remove PII**.210
13.***Remove PII**.39
13.***Remove PII**.84
13.***Remove PII**.169
13.***Remove PII**.175
13.***Remove PII**.209
I was told that they are still investigating the root cause. So we all need to wait patiently. I'll update here once I get something new.
I have changed my password twice and have been checking the activity log. In the last two days, I have not seen any unusual login from 13.101.xxx.xxx . That is good news to me. I would like to be informed as to the cause of the problem when the team finds the answer.
Cemal
Before this issue gets fixed by Microsoft tech team, here are the things you can do:
Learn more about What happens if there's an unusual sign-in to your account (microsoft.com)