External sign in request.

jack singleton 0 Reputation points
2026-04-22T21:09:40.99+00:00

I have a microsoft account and use the authenticator app for security, at least 20 times a day someone tries to sign into my account, they cant because of the authenticator app but i want to stop people from trying to sign in. Ive changed my password to something very strong and it didn't change anything. Im still getting sign in requests every day. How can I stop this?

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Oldest
  1. AI answer

    2026-04-22T21:09:58.5633333+00:00

    The sign-in requests cannot be fully stopped from the outside, but they can be safely ignored and the account can be further secured and monitored.

    1. Do not approve any unrequested prompts or codes
      If verification codes or Authenticator prompts are received that were not initiated, do not approve or respond. As long as the attacker does not have access to the second factor, the account remains protected.
    2. Check recent activity and secure the account
      Review the account’s sign-in history to confirm whether any attempts have succeeded and to report suspicious activity:
    • Go to the Recent activity page from the Microsoft account security area and review sign-ins.
    • If any activity is not recognized, mark it as not you and follow the guided steps to secure the account.

    If there is concern that someone may already have the password, change it again from a trusted device and network, and ensure it is unique to this account.

    1. Strengthen sign-in security (two-step verification)
      Ensure two-step verification is fully enabled so every sign-in requires both the password and a second factor:
    • Sign in to the Security tab of the Microsoft account.
    • Select Manage how I sign in.
    • Under Additional securityTwo-step verification, choose Turn on and complete setup.

    Two-step verification makes repeated password-guessing attempts ineffective as long as the second factor is not compromised.

    1. Consider passwordless methods
      To reduce exposure to password-based attacks and unwanted code prompts, move toward passwordless sign-in methods (such as Microsoft Authenticator or other passwordless options) where available. These methods are more resistant to guessing and phishing than passwords.
    2. Understand that external attempts may continue
      Attackers or bots can keep trying to sign in using just the username; these attempts cannot be blocked at the account level. Microsoft detects unusual activity and may send alerts when sign-in attempts occur from new locations or devices. These alerts are part of the protection system and do not mean the account has been breached if the second factor is never approved.

    If the volume of prompts becomes unmanageable or there is suspicion of a broader compromise, contact the appropriate support channel or organizational IT administrator (for work/school accounts) to review sign-in logs and policies.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.