Managing personal Outlook.com account settings, security, and privacy
Assuming he hasn't exposed the alias it's possible they could be generating possible variants and attempting logins to see which succeed in a response.
Whether or not that's the case two things need to happen, and it's worrying that MS haven't addressed this.
When Microsoft detect these regular constant logins from different countries, they should alert the account holder with an "is this you" warning mail and if the answer is no then guide the user to ensure they have at least one 2 factor authentication method set up AND allow/guide/force the user to geo-restrict logins.
If the user wants to use a VPN perhaps they could have the option of choosing a restricted number of different country or countries.
I cannot understand why microsoft have not stopped this, they could easily detect this abuse, in fact they are in the best position of all to detect and stop it.
On a human level whilst 2FA might secure the account it doesn't prevent the user worrying that they are being targeted.