Unauthorized SUCCESSFUL signins even after enabling 2FA and PW change

Gerald Fay 0 Reputation points
2026-02-26T16:14:50.7966667+00:00

I'm seeing on my Recent Acctivity page "Successful Sign-in"s from places around the globe, even after I enabled 2FA and changed my PW. I also received an email from Microsoft in Chinese (about OneDrive) and a notification that I needed to enter my "app" PW to sign into a device b/c I enabled 2FA.

How do I tell MSFT that these "Successful Signins" reported on my Recent Activity page ARE NOT ME? "Help" instructions say that option should be under the activity, but it's not.

Please help me stop these apparently "Successful Signin" from occurring even after I've taken all the security precautions.

Microsoft Security | Microsoft Identity Manager

1 answer

Sort by: Newest
  1. AI answer

    2026-02-26T16:15:09.4166667+00:00

    On the Recent activity/My sign-ins pages, Microsoft only shows the “This was me/This wasn’t me” buttons in the Unusual activity section. If the sign-ins are listed only under Recent activity (normal activity), that confirmation option will not appear.

    To handle the situation with ongoing successful sign-ins and possible compromise:

    1. Review and secure the account immediately
      • For a personal Microsoft account, go to the Recent activity page and expand each sign-in to review location, device, and app details.
      • For a work/school account, sign in to My Account and open My sign-ins. Expand each entry and verify the operating system, browser, and app as well as location.
      • If any sign-in is unfamiliar, treat the account as compromised.
    2. Change password and security info again
      • Change the password to a strong, unique one that is not used on any other site.
      • Go to the Security settings / Security info pages and:
        • Remove any phone numbers, email addresses, or authentication methods that are not recognized.
        • Add trusted alternate email and mobile phone details.
      • For personal accounts, this is done from the Security settings page and Security basics.
      • For work/school accounts, use the Security info page.
    3. Use and keep multi-factor authentication (2FA) enabled
      • If there are unsuccessful sign-ins or “Additional verification failed, invalid code” entries, that can mean someone has the correct password but is failing MFA. In that case, change the password again and verify all MFA methods on the Security info page.
      • If 2FA is not yet enabled on a personal account, turn on two-step verification as described in the security documentation.
    4. Understand why locations may look wrong
      • The sign-in location is based on IP and can be inaccurate, especially on mobile networks or when traffic is routed through distant locations. A sign-in from another state or country can still be legitimate if the device, OS, browser, and app match normal usage.
      • Always check those extra details before concluding a sign-in is an attacker.
    5. Use the “Secure your account” flow when available
      • On the personal account Recent activity page, if an Unusual activity section appears, expand each event and choose This wasn’t me for any sign-in that is not recognized. That triggers Microsoft’s protection steps and guides through securing the account.
      • If only Recent activity is shown (no Unusual activity section), the “This wasn’t me” option will not be present; in that case, rely on the steps above: password change, security info review, and MFA.
    6. If unusual sign-in alerts continue
      • Keep monitoring the Recent activity/My sign-ins pages for new successful sign-ins from unknown devices or apps.
      • If suspicious activity persists even after changing password and cleaning up security info, repeat the secure-account steps and consider that another device or app may still be signed in with old tokens; sign out of all sessions where that option is available and re-sign in only on trusted devices.

    These steps both inform Microsoft’s systems (via the Unusual activity flow when available) and harden the account so that even if someone has the password, they cannot continue to sign in.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.