Live.com login activity and a warning "Unusual activity detected"

Anonymous
2022-07-10T21:32:50+00:00

I could not find a more direct forum than Outlook to ask this question, if it is not the right forum my apologies.

I received an e-mail alert that indicated unusual activity detected on my live.com account. When I checked the recent activity, I found two IP numbers. One matched my external IP and the other did not. I changed my password right away and checked the activity again. To my surprise, the other IP and its variants were appearing along with my external IP number at the same intervals.

I tried to find the IP number roots and ironically, it pointed at Microsoft. I am really confused! Can someone explain the source of this IP and whether I need to do anything to stop it from occurring.? I use Edge browser and I log in with my account. When it syncs, does it use a separate IP from my IP number?

Thank you,

Cemal

Note: I am not using the Outlook mail client. I check my mail using two different mail clients on two different computers at the same location that share the same external IP number. On occasion, I check my live.com e-mail online using a Web browser.

Outlook | Windows | Classic Outlook for Windows | For business

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

46 answers

Sort by: Newest
  1. Anonymous
    2022-07-18T16:16:30+00:00

    I have changed my password , added 2 step security and it is still happening. The activity originates in Redmond Washington US with similar VP addresses and at similar times of day

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2022-07-18T16:10:31+00:00

    Thanks, I'll wait.

    In the meantime I looked at the timestamps of "unusual activity" and my own accesses and they seem to be somewhat related, but not completely in sync.

    For yesterday I see:

    Activity from account.live.com my own accesses
    (no record) July 17, 2022 11:51:40 PM EDT
    (no record) July 17, 2022 11:41:35 PM EDT
    (no record) July 17, 2022 11:31:31 PM EDT
    (no record) July 17, 2022 11:21:27 PM EDT
    Protocol: POP3<br><br>Time: Yesterday 11:11 PMType: Successful sync July 17, 2022 11:11:22 PM EDT
    (no record) July 17, 2022 11:01:16 PM EDT
    Protocol: POP3<br>IP: 13.*********.102<br>Time: Yesterday 10:51 PM<br><br>Type: Unusual activity detected<br><br><br><br>Protocol: POP3<br>IP: 13.*******.39<br>Time: Yesterday 10:51 PMType: Unusual activity detected July 17, 2022 10:51:12 PM EDT
    (no record) July 17, 2022 10:41:07 PM EDT
    Protocol: POP3<br>IP: 13.*******.102<br>Time: Yesterday 10:31 PMType: Unusual activity detected<br><br><br><br>Protocol: POP3<br>IP: 13.*******.39<br>Time: Yesterday 10:31 PMType: Unusual activity detected July 17, 2022 10:31:02 PM EDT
    (no record) July 17, 2022 10:20:57 PM EDT
    Protocol: POP3<br>IP: 13.*******.84<br>Time: Yesterday 10:10 PMType: Unusual activity detected July 17, 2022 10:10:52 PM EDT
    (no record) July 17, 2022 10:00:46 PM EDT
    (no record) July 17, 2022 09:50:42 PM EDT
    (no record) July 17, 2022 09:40:38 PM EDT
    Protocol: POP3<br>IP: 13.********.102<br>Time: Yesterday 9:30 PMType: Unusual activity detected<br><br><br><br>Protocol: POP3<br>IP: 13.*******.39<br>Time: Yesterday 9:30 PMType: Unusual activity detected July 17, 2022 09:30:33 PM EDT
    (no record) July 17, 2022 09:20:28 PM EDT
    (no record) July 17, 2022 09:10:23 PM EDT
    Protocol: POP3<br>IP: 13.*******.102<br>Time: Yesterday 9:00 PMType: Unusual activity detected<br><br><br><br>Protocol: POP3<br>IP: 13.******.39<br>Time: Yesterday 9:00 PMType: Unusual activity detected July 17, 2022 09:00:17 PM EDT
    Protocol: POP3<br>IP: 13.********.210<br>Time: Yesterday 8:50 PMType: Unusual activity detected July 17, 2022 08:50:12 PM EDT
    (no record) July 17, 2022 08:40:05 PM EDT
    (no record) July 17, 2022 08:30:01 PM EDT

    Etc.

    So, the way I see it, for some random subset of my own accesses:

    either

    the access triggers some internal MSFT activity from their IP addresses that logs as "unusual activity"

    or

    a faulty log is generated .

    I have seen at least 7 MSFT IP addresses in the logs.

    13.***Remove PII***.102

    13.***Remove PII**.210

    13.***Remove PII**.39

    13.***Remove PII**.84

    13.***Remove PII**.169

    13.***Remove PII**.175

    13.***Remove PII**.209

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2022-07-16T07:59:46+00:00

    I was told that they are still investigating the root cause. So we all need to wait patiently. I'll update here once I get something new.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2022-07-15T13:57:31+00:00

    I have changed my password twice and have been checking the activity log. In the last two days, I have not seen any unusual login from 13.101.xxx.xxx . That is good news to me. I would like to be informed as to the cause of the problem when the team finds the answer.

    Cemal

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2022-07-15T08:18:27+00:00

    Before this issue gets fixed by Microsoft tech team, here are the things you can do:

    1. Change your Microsoft account password
    2. Add security info to your Microsoft account
    3. Sign out your Microsoft account from all the apps and all the devices
    4. Check if you were using VPN

    Learn more about What happens if there's an unusual sign-in to your account (microsoft.com)

    Was this answer helpful?

    0 comments No comments