A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Those repeated unknown sign-in prompts mean someone or something is repeatedly trying to sign in with the account credentials, but the extra verification step is blocking access as designed.
What to do now:
- Review recent sign-in activity
- For a work or school account, go to the My Account portal → Recent activity and review each sign-in.
- Confirm that the suspicious attempts are not legitimate false positives (for example, mobile IPs can appear from other regions). Check location, operating system, browser, and app details, not just the country.
- If you see any successful sign-in you do not recognize, immediately change the password and then go to the Security info page to update security settings.
- Treat repeated unsuccessful attempts as a security signal
- Unsuccessful sign-ins can mean either mistyped credentials or that an attacker is trying to guess the password.
- If you see entries like “Additional verification failed, invalid code,” it means the password was correct but the second factor stopped the sign-in. In that case, change the password right away and review/update security info.
- Strengthen protection
- Ensure multi-factor authentication is enabled and kept active. With MFA, even if a password is guessed, it is not enough to access the account.
- Regularly review and update security info (phone, alternate email, authenticator) from the Security info or Security basics pages, and remove methods that are no longer under control.
- If sign-in attempts are very frequent
- Microsoft Entra multifactor authentication can detect unusual activity like repeated sign-in attempts and may temporarily block additional attempts to counter security threats.
- If there is suspicion that someone is actively trying to access a work or school account, contact the organization’s IT administrator and ask them to review Microsoft Entra sign-in logs.
These steps will not stop attackers from trying, but they ensure that attempts remain unsuccessful and that any real compromise is detected and contained quickly.
References: