Live.com login activity and a warning "Unusual activity detected"

Anonymous
2022-07-10T21:32:50+00:00

I could not find a more direct forum than Outlook to ask this question, if it is not the right forum my apologies.

I received an e-mail alert that indicated unusual activity detected on my live.com account. When I checked the recent activity, I found two IP numbers. One matched my external IP and the other did not. I changed my password right away and checked the activity again. To my surprise, the other IP and its variants were appearing along with my external IP number at the same intervals.

I tried to find the IP number roots and ironically, it pointed at Microsoft. I am really confused! Can someone explain the source of this IP and whether I need to do anything to stop it from occurring.? I use Edge browser and I log in with my account. When it syncs, does it use a separate IP from my IP number?

Thank you,

Cemal

Note: I am not using the Outlook mail client. I check my mail using two different mail clients on two different computers at the same location that share the same external IP number. On occasion, I check my live.com e-mail online using a Web browser.

Outlook | Windows | Classic Outlook for Windows | For business

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

46 answers

Sort by: Oldest
  1. Anonymous
    2022-07-13T01:14:06+00:00

    I see 4 people marked "I have the same question". I've submitted this issue to Microsoft Tech team so that they can investigate it. I'll update once I get an answer.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  2. Anonymous
    2022-07-13T01:50:33+00:00

    Thank you, we will be waiting.

    Cemal

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2022-07-13T17:30:02+00:00

    I also just got email about "Microsoft account unusual sign-in activity", and reviewing activity I see:

    Protocol: POP3
    

    IP: 13..39Account alias:@live.com Time: 2 hours agoApproximate location: United StatesType: Unusual activity detected

    What I find interesting is that the IP address belongs to Microsoft:

    Source Registry
    ARIN
    Net Range
    13.*********.0 - 13.*********.255
    CIDR
    13.*********.0/11
    13.*********.0/13
    13.*********.0/14
    Name
    MSFT
    Handle
    NET-13-64-0-0-1
    

    Could it be some normal internal activity at Microsoft that is being mis-reported as unusual?

    -T

         ***\*\*\*\*Remove PII\*\*\*\****
    

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2022-07-13T18:52:50+00:00

    Seeing the same issue with two accounts I had mostly for archiving purposes. Same thing with the Microsoft IP addresses. The email addresses in question had not been used to sign up for any other accounts or anything so it seems highly unlikely it could be a leak from from some other source. Also the unusual activity keeps recurring even after I have gone through the process of changing my password and indicating that the attempted login was not me.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  5. Anonymous
    2022-07-13T19:42:47+00:00

    One thing I noticed was when I use my regular mail client, I get the unusual activity report. I closed and did not use the mail client for almost a day, and the unusual activity from the connection reports. When I start using the mail client unusual activity starts showing up. I started a ticket with the mail client software company as well.

    Was this answer helpful?

    0 comments No comments