My outlook account notices some unusual IMAP Login from Microsoft at Redmond

Anonymous
2022-07-12T08:27:40+00:00

I'm noticed from Microsoft Account Service that my outlook account has been exposed some IMAP Logins from each of the IPv4 addresses at 13.101.0.0-13.101.255.255 since 2022-07-11 JST informed as "unusual activity".

And I found with using whois service that these IP may be managed by Microsoft and placed at Redmond city in US.

Yeah I changed PW in usual way but these access can't stop anyway, so I'm guessing this is a specification for Outlook service.

But at the same time I am afraid of some attacks to Outlook service or Microsoft's collection of users data.

Does Anyone know some information about these kinds of access?

I already used technical help service of online chats in Japan, but he said that he doesn't have some clear idea.

Notification

Thanks to any users to read this thread and report the same issue.

I guess you all are as anxious as I am, but I'd like you to just keep focus on the topic of "unusual activity" from 13.101.0.0/16 here.

While many attacks on login to some system will happen all the time around the world, Thus this case is unique in that it's coming from IPv4 addresses inside Microsoft.

And here we hope to solve this strange problem.

Thank you for your cooperation.

S.E.

Outlook | Web | Outlook.com | Account management, security, and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2022-07-19T22:42:18+00:00

User @Chezlong Just placed this on my forum post

https://answers.microsoft.com/en-us/outlook_com/forum/all/unusual-account-activity-from-ms-ip-addresses/974cc1c1-232f-44a2-b0eb-0f378fd2c801?page=5:

Finally got to talk to someone at MS- this was their reply:

Thank you for the information. Please be advise that Microsoft is aware of this known issue already. This started to happen even last week and we are already working with this matter. We even have created a ticket number for this issue while it is still happening.

The ticket number for the emerging issue is INC31680156.

So they are on it, but no idea when it will be fixed.

[EDIT] They also confirmed that the account was secure, no need to change passwords, etc

AND

Found the following on thread https://answers.microsoft.com/en-us/outlook\_com/forum/all/outlook-mail-account-unusual-activity/6cfb226f-8cd7-41ae-bd0a-a80d100af543?page=9

posted by user @Pierre-LucMorais:

I have looked for other means to communicate to MS and I found an “official” thread to post this problem. Your mile may vary but i’ve had a reply on my thread and encourage ppl to try using them as well ?

https://www.reddit.com/r/microsoft/comments/o22lfc/microsoft\_official\_support\_thread/

They’ve responded that it is a backend accessing the service and a known issue.

Hoping this helps

Was this answer helpful?

10 people found this answer helpful.
0 comments No comments
Answer accepted by question author
Anonymous
2022-07-22T15:39:05+00:00

Outlook email users alerted to suspicious activity from Microsoft-owned IP address—
People turn amateur sleuths to discover that the source of all those sign-ins seems to be in Redmond
https://www.theregister.com/2022/07/21/outlook_sign_ins/
Article has an update at the end:

Updated at 09.33 UTC on 22 July 2022 to add:
Following publication of this article, Microsoft sent us a statement:
"We're working to resolve a configuration issue causing some customers to receive these notifications in error," said a Microsoft spokesperson via email.

Was this answer helpful?

2 people found this answer helpful.
0 comments No comments

56 additional answers

Sort by: Most helpful
  1. Anonymous
    2022-07-16T18:40:24+00:00

    I found a post from 2015, where a replier had received this answer:>>>>Good day! I understand the situation you are in and let me do my best to help you. Please be informed that IP addresses from Microsoft are generated from when your account is accessed by our system to apply updates to the account. This is the system accessing the account, not any particular individual from Microsoft accessing the account. <<<<

    You found the above quote in this old post from 2015 about unusual access of outlook accounts from 132.245.x.x

    https://answers.microsoft.com/en-us/outlook_com/forum/all/microsoft-account-unusual-sign-in-activity-ip-is/893dd29e-ff5c-48b5-a7d6-4588d5e83fc6?page=2

    but reports of that event aren't similar in a few ways -

    1. The unusual sign-in's didn't accompany our own sign-ins on POP/IMAP. This pattern matches one of the vulnerabilities of old protocols such as SMTP, POP and IMAP (e.g. read more online if interested about drown attacks on TLS that exposes the plaintext passwords we've been using with these protocols on Outlook all this time), which email providers like Google and Microsoft are trying to address by offering Oauth2 (Microsoft is not yet offering personal email accounts the same OAuth2 as they are offering business email account holders, but Microsoft said it would by Oct 1 2022), and in the case of Microsoft trying to move everyone to Graph API from the old Exchange Web Services.
    2. The source IP wasn't from the 13.101.x.x Azure blocks, it was Microsoft's other servers,
    3. Very old hotmail accounts that aren't getting the unusual sign-ins are getting requests from AWS SES and Pinpoint to agree to be accessed from AWS. This combined with the above happening at the same time reflects more intentional activity.

    I have a support ticket too with Microsoft too. If you get a confirmation from Microsoft on your ticket that this is just Microsoft fiddling with things, please do let us know too on this thread. In the meantime, I'd suggest POP all emails to your personal computers, so that if any intruder is accessing your emails, they can't get all you historical emails too.

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2022-07-13T11:13:55+00:00

    I connect to my Outlook account from only macOS with default mail client

    And really I'm not sure about using Azure account or Azure Device.

    I just heard about it from my roommate that he had same problem.

    OK, now I try to use 2 factor authentication, and I recommend him the same way.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  3. Anonymous
    2022-07-12T21:56:26+00:00

    Hi Soluna Eureka , Thank you for posting to the Microsoft community. Based on the description, you are having an issue on your account notices  some unusual IMAP Login from Microsoft at Redmond. This usually happens when there's a user trying to access on your account using your Azure account or device. Let's check this out together and find ways to solve this. Before anything else, let me ask you the following questions below so that I fully understand the problem.

    1. When does the issue started?
    2. What are the steps have you done so far?

    We are truly grateful that you have taken the time to convey this concern to us. I would suggest to  update your password, enable 2 factor to make sure you are protected.

    We look forward to your response. If you have other clarifications on this question, you can get back to us by replying to this post.Truly Yours,FatimaMicrosoft Moderator

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments