Repeated unauthorized attempts at Authenticator sign in

Robert Olson 10 Reputation points
2026-03-09T15:50:49.1+00:00

Repeated unauthorized attempts at authentication sign in

Microsoft Security | Microsoft Authenticator

1 answer

Sort by: Most helpful
  1. AI answer

    2026-03-09T15:51:05.9+00:00

    Microsoft Entra multifactor authentication and Microsoft accounts can temporarily block or challenge sign-ins when there are repeated or unusual attempts, including those coming from unknown devices or locations.

    For repeated unauthorized or suspicious Authenticator prompts:

    1. Do not approve any unexpected prompts
      Treat any unrecognized approval request as a possible attack. If a prompt appears and no sign-in was initiated, deny it.
    2. Wait out temporary blocks and avoid repeated attempts
      Multiple failed or suspicious attempts can trigger smart lockout or other protections. Further repeated attempts can extend the block. Wait before trying again, and avoid repeatedly requesting codes or approvals.
    3. Use a different verification method (if available)
      If one method (for example, Authenticator push) appears to be targeted or blocked, use another registered method such as SMS, phone call, or alternate email to sign in and then review account security. Guidance for this scenario is described under “Try another method” and “Try another verification method” error handling.
    4. Check for unusual sign-ins and lockouts (admins)
      For work or school accounts, an IT administrator should:
      • Review Microsoft Entra Sign-in logs for the affected user to look for:
        • Many Failed authentications (possible password spray or brute force).
        • Many Interrupted authentications where MFA is required but not completed (possible compromised password).
        • Smart lock-out events indicating repeated attempts from unfamiliar locations.
        • Large volumes of sign-ins from many IPs or unusual IP changes.
      • Investigate and, if needed, reset the user’s password and require re-registration of MFA.
    5. If blocked with “Try another verification method”
      Repeated or high-volume attempts, or activity from risky locations, can cause temporary or longer-term blocks:
      • Try another verification method tied to the account (alternate email, different phone number, etc.).
      • Try another network (switch Wi‑Fi/cellular or use a different trusted network).
      • Wait at least 24 hours without repeated attempts; if still blocked, wait longer (up to a week) before trying again.
      • Use the sign-in helper linked in the guidance to walk through recovery options.
    6. If unable to sign in after multiple attempts (work/school)
      • Microsoft Entra MFA may be preventing further attempts due to detected unusual activity.
      • Wait before trying again or use a different MFA method.
      • Contact the organization’s IT administrator or help desk to investigate sign-in logs and adjust MFA or Conditional Access policies if needed.
    7. If the account may be compromised
      • For work/school: IT should investigate sign-in logs, reset credentials, and enforce MFA.
      • For personal Microsoft accounts: follow the verification-code troubleshooting guidance, avoid repeated recovery attempts that can extend blocks, and use alternative verification methods and the sign-in helper.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.