A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Multiple unexpected Microsoft Authenticator prompts or verification codes usually mean that someone is repeatedly trying to sign in with the correct email address but does not have access to the second factor.
Key points from Microsoft guidance:
- Treat this as possible malicious activity
- Repeated sign-in attempts and MFA prompts are explicitly called out as unusual activity that Microsoft Entra multifactor authentication may detect and temporarily block to counter security threats.
- If this is not activity initiated personally, assume someone is trying to access the account.
- Do not approve any prompts or codes
- Microsoft explicitly advises not to respond to or approve verification codes or prompts that were not requested. Without approval, the attacker cannot complete sign-in.
- Immediately secure the account
Perform these steps as soon as possible:
- Change the account password to a strong, unique one that is not used on any other site.
- Review recent sign-in activity:
- For work/school accounts, use the My sign-ins experience to review recent successful and unsuccessful sign-ins. If any activity is unfamiliar, change the password (if not already done) and update security info at the Security info page.
- Ensure multi-factor authentication (two-step verification) is enabled and working, and verify all registered methods (phone, email, Authenticator app, security keys) are correct and belong to the legitimate owner.
- Consider going passwordless for stronger protection
- Microsoft recommends moving to passwordless sign-in (for work or school accounts) using options such as Windows Hello, Microsoft Authenticator, SMS/Email codes, or physical security keys. Passwordless methods reduce the risk from password guessing or reuse.
- If sign-in is blocked after many attempts
- Microsoft Entra MFA may temporarily prevent additional attempts after repeated sign-ins. In that case, wait for the lockout to clear and/or use an alternate MFA method if one is configured.
- Involve the organization’s IT/admin team (for work or school accounts)
- If this is a work or school account, contact the organization’s Help desk or IT administrator:
- Ask them to review Microsoft Entra sign-in logs for suspicious activity.
- Ask them to clear or reset MFA settings if needed so that secure methods can be re-registered.
- If this is a work or school account, contact the organization’s Help desk or IT administrator:
- Monitor for ongoing attempts
- Continue to review sign-in activity. If repeated unsuccessful attempts continue but MFA is blocking them, the account is still protected, but it is important to keep password and security info up to date.
If there is any suspicion that someone has already accessed the account (for example, unfamiliar successful sign-ins), change the password immediately and review all security settings and recent activity as recommended.
References: