A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Those repeated prompts are a sign that someone has your password and is repeatedly trying to complete sign-in but is being blocked by multifactor authentication (MFA). The goal is to stop the attack and then harden the account so it cannot continue.
- Do not approve any Authenticator requests
- Treat every unexpected prompt as an attack. Ignore or explicitly deny them.
- Never read verification codes to anyone who contacts by phone, text, or email. Attackers often pretend to be support or a bank and ask for the code.
- Change the account password immediately
- Change the password for the affected account to a strong, unique password that is not used on any other site.
- This cuts off the attacker’s ability to keep triggering new MFA prompts using the stolen password.
- Review recent sign-in activity
- For personal Microsoft accounts, check the recent activity page (for Outlook.com this is at the same place referenced as
https://account.live.com/activity). - Look for unfamiliar locations, devices, or apps. If any sign-in is not recognized, mark it as “This wasn’t me” where available and follow the guidance to secure the account.
- For personal Microsoft accounts, check the recent activity page (for Outlook.com this is at the same place referenced as
- Strengthen MFA and security info
- Ensure multifactor authentication is turned on and working for the account.
- Prefer an authenticator app (such as Microsoft Authenticator) over SMS where possible, as it is more resistant to interception.
- Verify and update security info: alternate email addresses and phone numbers so account recovery is possible if needed.
- Sign out everywhere and revoke suspicious access
- Use the account’s security pages to sign out of all active sessions so any attacker’s sessions are terminated.
- Review app permissions and remove any apps or services that are not recognized.
- Check for signs of compromise in email
- If this is an Outlook.com or Microsoft 365 mailbox, review:
- Mail rules for any that forward, delete, or move messages unexpectedly.
- Forwarding settings for unknown forwarding addresses.
- Remove anything suspicious and then change the password again if new activity is found.
- If this is an Outlook.com or Microsoft 365 mailbox, review:
- Monitor for continued attempts
- After changing the password and signing out everywhere, MFA prompts should stop. If they continue, repeat the password change and review security info again.
- For work or school accounts, administrators can use sign-in logs and Conditional Access to:
- Block sign-ins from unexpected countries/regions.
- Require MFA only for risky or high-value actions.
- Monitor for excessive authentication failures and alert on them.
- Device and network hygiene
- Make sure devices used to sign in are updated and protected with antivirus.
- If a device is suspected to be compromised, run a full malware scan and consider a reset.
Identifying the exact individual attacker is generally not possible from the client side, but reviewing sign-in activity will show approximate locations, IPs, and device types so that risk can be assessed and blocked where appropriate. The key is to assume the password is known, replace it, and then rely on strong MFA and account hygiene to prevent further abuse.
References:
- Microsoft Authenticator FAQs
- The keys to the kingdom - securing your devices and accounts
- What happens if there's an unusual sign-in to your account
- Help protect your Outlook.com email account
- View your work or school account sign-in activity from My Sign-ins
- Microsoft Entra External ID deployment guide for security operations
- How to help keep your Microsoft account secure