A free app and service that helps families create healthy digital habits and stay connected. It’s designed to support both online safety and real-world awareness by offering tools for screen time management, content filtering, and location sharing
Based on the available information, only the sign-in and account‑security aspects can be addressed.
- Successful sign-in without a visible 2FA prompt
From the sign-in activity guidance:
- A successful sign-in from an unfamiliar location, browser, or OS can still be legitimate if:
- The IP geolocation is inaccurate (for example, mobile networks or certain ISPs can route traffic through distant locations).
- The device or browser is using an existing, valid session or token.
- Multi-factor authentication (2FA) is not always prompted on every sign-in if:
- A previously trusted device/session is being reused.
- The sign-in satisfies existing risk and policy checks (for example, same device, similar network, or previously completed MFA).
In such cases, the sign-in can appear as “successful” in the activity log without a new interactive 2FA challenge, because the existing session or refresh token is still considered valid.
The documentation also notes that:
- If an attacker guesses the password but fails MFA, the activity can show as unsuccessful with “Additional verification failed, invalid code.”
- If a successful sign-in appears from an unfamiliar location/device, the recommended response is to immediately change the password and update security info.
- How to respond to the suspicious successful sign-in
For a personal Microsoft account:
- Review recent activity
- Go to the Security basics page and select Review activity to open the Recent activity page.
- Carefully review all sign-ins, especially the unfamiliar successful one.
- If any activity is clearly not yours:
- For entries in Unusual activity, expand and select This wasn’t me.
- For entries in Recent activity, expand and select Secure your account.
- Secure the account
- From Security basics, select Change password and set a strong, unique password (already done, but recommended again after any suspicious sign-in).
- Ensure 2FA (two-step verification) is enabled and that all security info (phone, email, Authenticator) is up to date.
- Use “sign out everywhere” or equivalent options where available to invalidate existing sessions, then sign in again only from trusted devices.
- Interpreting the risk level
- A single successful sign-in from an unfamiliar IP or browser does not automatically mean 2FA is broken; it can be due to:
- IP geolocation inaccuracies.
- Existing trusted sessions or tokens that did not require a fresh MFA prompt.
- However, if any sign-in is truly not yours, the account must be treated as potentially compromised until:
- Password is changed.
- Security info is verified/updated.
- Suspicious activity is reported via the Recent activity page.
- Additional steps
- Continue to monitor the Recent activity page for any new unfamiliar sign-ins.
- If repeated suspicious sign-ins appear (successful or unsuccessful), consider:
- Reviewing and tightening security info and verification methods.
- Ensuring all devices used to access the account are malware‑free (full AV scans, OS and browser updates).
The context provided does not document Microsoft Family/Families being re‑joined automatically or family membership behavior, so only the sign‑in and account‑security guidance above can be confirmed.
References: