A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
The sign-in requests cannot be fully stopped from the outside, but they can be safely ignored and the account can be further secured and monitored.
- Do not approve any unrequested prompts or codes
If verification codes or Authenticator prompts are received that were not initiated, do not approve or respond. As long as the attacker does not have access to the second factor, the account remains protected. - Check recent activity and secure the account
Review the account’s sign-in history to confirm whether any attempts have succeeded and to report suspicious activity:
- Go to the Recent activity page from the Microsoft account security area and review sign-ins.
- If any activity is not recognized, mark it as not you and follow the guided steps to secure the account.
If there is concern that someone may already have the password, change it again from a trusted device and network, and ensure it is unique to this account.
- Strengthen sign-in security (two-step verification)
Ensure two-step verification is fully enabled so every sign-in requires both the password and a second factor:
- Sign in to the Security tab of the Microsoft account.
- Select Manage how I sign in.
- Under Additional security → Two-step verification, choose Turn on and complete setup.
Two-step verification makes repeated password-guessing attempts ineffective as long as the second factor is not compromised.
- Consider passwordless methods
To reduce exposure to password-based attacks and unwanted code prompts, move toward passwordless sign-in methods (such as Microsoft Authenticator or other passwordless options) where available. These methods are more resistant to guessing and phishing than passwords. - Understand that external attempts may continue
Attackers or bots can keep trying to sign in using just the username; these attempts cannot be blocked at the account level. Microsoft detects unusual activity and may send alerts when sign-in attempts occur from new locations or devices. These alerts are part of the protection system and do not mean the account has been breached if the second factor is never approved.
If the volume of prompts becomes unmanageable or there is suspicion of a broader compromise, contact the appropriate support channel or organizational IT administrator (for work/school accounts) to review sign-in logs and policies.
References: