My outlook account notices some unusual IMAP Login from Microsoft at Redmond

Anonymous
2022-07-12T08:27:40+00:00

I'm noticed from Microsoft Account Service that my outlook account has been exposed some IMAP Logins from each of the IPv4 addresses at 13.101.0.0-13.101.255.255 since 2022-07-11 JST informed as "unusual activity".

And I found with using whois service that these IP may be managed by Microsoft and placed at Redmond city in US.

Yeah I changed PW in usual way but these access can't stop anyway, so I'm guessing this is a specification for Outlook service.

But at the same time I am afraid of some attacks to Outlook service or Microsoft's collection of users data.

Does Anyone know some information about these kinds of access?

I already used technical help service of online chats in Japan, but he said that he doesn't have some clear idea.

Notification

Thanks to any users to read this thread and report the same issue.

I guess you all are as anxious as I am, but I'd like you to just keep focus on the topic of "unusual activity" from 13.101.0.0/16 here.

While many attacks on login to some system will happen all the time around the world, Thus this case is unique in that it's coming from IPv4 addresses inside Microsoft.

And here we hope to solve this strange problem.

Thank you for your cooperation.

S.E.

Outlook | Web | Outlook.com | Account management, security, and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2022-07-19T22:42:18+00:00

User @Chezlong Just placed this on my forum post

https://answers.microsoft.com/en-us/outlook_com/forum/all/unusual-account-activity-from-ms-ip-addresses/974cc1c1-232f-44a2-b0eb-0f378fd2c801?page=5:

Finally got to talk to someone at MS- this was their reply:

Thank you for the information. Please be advise that Microsoft is aware of this known issue already. This started to happen even last week and we are already working with this matter. We even have created a ticket number for this issue while it is still happening.

The ticket number for the emerging issue is INC31680156.

So they are on it, but no idea when it will be fixed.

[EDIT] They also confirmed that the account was secure, no need to change passwords, etc

AND

Found the following on thread https://answers.microsoft.com/en-us/outlook\_com/forum/all/outlook-mail-account-unusual-activity/6cfb226f-8cd7-41ae-bd0a-a80d100af543?page=9

posted by user @Pierre-LucMorais:

I have looked for other means to communicate to MS and I found an “official” thread to post this problem. Your mile may vary but i’ve had a reply on my thread and encourage ppl to try using them as well ?

https://www.reddit.com/r/microsoft/comments/o22lfc/microsoft\_official\_support\_thread/

They’ve responded that it is a backend accessing the service and a known issue.

Hoping this helps

Was this answer helpful?

10 people found this answer helpful.
0 comments No comments
Answer accepted by question author
Anonymous
2022-07-22T15:39:05+00:00

Outlook email users alerted to suspicious activity from Microsoft-owned IP address—
People turn amateur sleuths to discover that the source of all those sign-ins seems to be in Redmond
https://www.theregister.com/2022/07/21/outlook_sign_ins/
Article has an update at the end:

Updated at 09.33 UTC on 22 July 2022 to add:
Following publication of this article, Microsoft sent us a statement:
"We're working to resolve a configuration issue causing some customers to receive these notifications in error," said a Microsoft spokesperson via email.

Was this answer helpful?

2 people found this answer helpful.
0 comments No comments

56 additional answers

Sort by: Newest
  1. Anonymous
    2022-07-19T01:10:17+00:00

    Please do fill out the Microsoft Abuse Form online so that we can further check the issue on our end and Microsoft engineering team are doing their best to rectify the issue as soon as possible and the investigation is still ongoing.

    To all community members here ...

    1. Are you submitting the abuse reports? Are you getting any responses from Microsoft after submitting them besides the automated response?
    2. Have you lost any emails from your email accounts that had a successful sync from 13.101.x.x?

    I ask question 1 above just to be sure that everyone is submitting them reporting all the 13.101.x.x IP addresses and want to make sure that Microsoft engineers getting these abuse reports aren't just closing out the reports out blaming Azure users. This is beyond just going into the activity report where you go and click that it wasn't you.

    I ask question 2, recognizing that POP3 and IMAP allow reading emails without deletion and without losing our emails we could still be facing major identity theft if this is an intruder in action. However, I sense that it's only when customers begin to lose emails or encounter ID theft that there will be incentive for Microsoft to act on the situation.

    From the relatively quiet Microsoft in over 1 week since this began, I sense that either Microsoft knows that this is something internal or this is something so serious they cannot talk about it, yet. I hope this is the former, but preparing for the latter. I also sense that POP and IMAP users aren't as valuable for Microsoft because we aren't ad targets unlike web mail users, and Microsoft is planning for OAuth2 in October anyway, so from a purely business perspective attending to the current situation is not a priority.

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2022-07-18T21:50:40+00:00

    HI!

    Plus one in the house!

    I'm having the same issues since 07/14/2022.

    I'm receiving emails from Microsoft Account Staff about unusual activities on my account.

    They were all Automatic Sync using POP3, from IP's that who.is points to be from Microsoft.

    In my case, these are the IP's

    • 13.101.76.232
    • 13.101.76.24
    • 13.101.148.70

    I just filled up the Abuse Report, and I'm now waiting for an answer from Microsoft!

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2022-07-18T21:01:28+00:00

    Very Thanks.

    It passes just a week after I posted this thread, but so depressing we have been given no clear idea or solution.

    According to you, now I can rely on the abuse report sent to Microsoft CERT or moderator staffs contacting to internal staffs, that's all.

    I hope it is a spec or just a bug, however longer it takes to resolve and more we tend to be worry.

    But the more information about this issue we have, the better I wish.

    Hi Soluna Eureka & Other community members!

    Good day!

    Please do fill out the Microsoft Abuse Form online so that we can further check the issue on our end and Microsoft engineering team are doing their best to rectify the issue as soon as possible and the investigation is still ongoing.

    >> Abuse ReportForm

    We appreciate your patience and cooperation.

    Sincerely,

    Juhn Jac,      

    Microsoft Forum Moderator

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments