Unexpected Microsoft Family reassignment + suspicious successful sign-in (with 2FA enabled)

Alex 0 Reputation points
2026-04-30T18:33:18.6133333+00:00

Hello,

I’m experiencing a very unusual issue with my Microsoft account and Microsoft Family, and I’d appreciate help from someone familiar with Family Safety / Microsoft 365 Family behavior.

1. Background

  • In 2025, I was a member of a Microsoft Family managed by another organizer.
  • In April 2026, I was removed from that family as per my request (I received a confirmation email).
  • After that, I activated my own Microsoft 365 Family subscription and created a new family.
  • I was the only organizer and added one member (a relative).

Everything worked as expected at that time.


2. What happened

Recently, I logged in and discovered that:

  • I was suddenly part of the old family again (the one from 2025)
  • I was not the organizer
  • There were unknown members in that family
  • My relative was also shown as part of that same family

Important:

  • I did NOT accept any new family invitations
  • I did NOT receive any invitation emails
  • There is no record of me joining any family manually

3. Strange behavior when leaving the family

When I clicked "Leave family":

  • My relative received a notification that I removed them from the family
  • However, they could still see themselves as a member
  • They had to manually leave as well

This behavior seems inconsistent and suggests possible synchronization issues.


4. Security context

  • I have 2FA enabled via Microsoft Authenticator
  • I changed my password recently (strong, unique password)
  • I signed out from all sessions
  • I carefully verify all Authenticator prompts and did NOT approve any suspicious login attempts

5. Suspicious sign-in

In my account activity, I noticed:

  • One successful login from an unfamiliar IP address
  • Browser listed as Microsoft Edge (I do not use Edge)
  • No 2FA prompt was received or approved by me

This is particularly concerning because I expect 2FA to prevent any successful login without my confirmation.


6. Questions

  1. Is it technically possible for a Microsoft account to be re-added to a previous family without explicit acceptance?
  2. Could this be caused by a synchronization issue between Microsoft Family and Family Safety services?
  3. Under what conditions can a successful login appear in activity without triggering a 2FA prompt?
  4. Could this be related to session tokens, cached authentication, or linked subscriptions?

7. Current status

  • I have left the family
  • My relative has also left
  • No unknown devices are currently signed in

I would really appreciate any clarification on:

  • Whether this is a known issue
  • Whether my account security might still be at risk
  • What additional steps I should take

Thank you in advance

Microsoft 365 and Office | Microsoft Family Safety | For home | Windows
0 comments No comments

1 answer

Sort by: Newest
  1. AI answer

    2026-04-30T18:36:11.87+00:00

    Based on the available information, only the sign-in and account‑security aspects can be addressed.

    1. Successful sign-in without a visible 2FA prompt

    From the sign-in activity guidance:

    • A successful sign-in from an unfamiliar location, browser, or OS can still be legitimate if:
      • The IP geolocation is inaccurate (for example, mobile networks or certain ISPs can route traffic through distant locations).
      • The device or browser is using an existing, valid session or token.
    • Multi-factor authentication (2FA) is not always prompted on every sign-in if:
      • A previously trusted device/session is being reused.
      • The sign-in satisfies existing risk and policy checks (for example, same device, similar network, or previously completed MFA).

    In such cases, the sign-in can appear as “successful” in the activity log without a new interactive 2FA challenge, because the existing session or refresh token is still considered valid.

    The documentation also notes that:

    • If an attacker guesses the password but fails MFA, the activity can show as unsuccessful with “Additional verification failed, invalid code.”
    • If a successful sign-in appears from an unfamiliar location/device, the recommended response is to immediately change the password and update security info.
    1. How to respond to the suspicious successful sign-in

    For a personal Microsoft account:

    1. Review recent activity
      • Go to the Security basics page and select Review activity to open the Recent activity page.
      • Carefully review all sign-ins, especially the unfamiliar successful one.
      • If any activity is clearly not yours:
        • For entries in Unusual activity, expand and select This wasn’t me.
        • For entries in Recent activity, expand and select Secure your account.
    2. Secure the account
      • From Security basics, select Change password and set a strong, unique password (already done, but recommended again after any suspicious sign-in).
      • Ensure 2FA (two-step verification) is enabled and that all security info (phone, email, Authenticator) is up to date.
      • Use “sign out everywhere” or equivalent options where available to invalidate existing sessions, then sign in again only from trusted devices.
    3. Interpreting the risk level
    • A single successful sign-in from an unfamiliar IP or browser does not automatically mean 2FA is broken; it can be due to:
      • IP geolocation inaccuracies.
      • Existing trusted sessions or tokens that did not require a fresh MFA prompt.
    • However, if any sign-in is truly not yours, the account must be treated as potentially compromised until:
      • Password is changed.
      • Security info is verified/updated.
      • Suspicious activity is reported via the Recent activity page.
    1. Additional steps
    • Continue to monitor the Recent activity page for any new unfamiliar sign-ins.
    • If repeated suspicious sign-ins appear (successful or unsuccessful), consider:
      • Reviewing and tightening security info and verification methods.
      • Ensuring all devices used to access the account are malware‑free (full AV scans, OS and browser updates).

    The context provided does not document Microsoft Family/Families being re‑joined automatically or family membership behavior, so only the sign‑in and account‑security guidance above can be confirmed.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.