A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Those unexpected Microsoft Authenticator notifications mean that either someone is trying to sign in to the account, or a sign-in attempt was made with an email/phone similar to the account and the prompt is being sent by mistake.
Do not approve any sign-in requests that were not initiated intentionally. Approving a request would grant access to the account.
Recommended actions:
- Deny every unrequested prompt
When the notification appears, always choose Deny if the sign-in was not initiated. - Review recent account activity
Go to the account’s recent activity page and check for unfamiliar sign-ins or security events. If anything looks suspicious, use the option there to secure the account. - Strengthen sign-in security
Consider moving to passwordless sign-in methods such as Microsoft Authenticator number matching, Windows Hello, SMS/Email codes, or physical security keys. These methods are designed to be more secure and reduce the risk from password guessing or phishing. - Use Authenticator/Outlook correctly when signing in
When intentionally signing in, always verify the number shown on the sign-in screen and tap the matching number in Authenticator (or Outlook mobile, if enabled) before approving. This helps prevent accidental approval of a malicious prompt.
If unrequested prompts continue after securing the account and changing the password, keep denying them and periodically review recent activity to ensure no unauthorized access is occurring.
References: