A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
These repeated Microsoft Authenticator prompts mean someone (or something like a script/app) is repeatedly trying to sign in with the correct username and password, and Authenticator is blocking them at the second factor step.
Based on the provided information, the following actions are supported:
- Verify and secure the Microsoft account
- Go to the Security basics page: https://account.microsoft.com/security.
- Select Review activity and check the Recent activity page. Look for:
- Unusual activity detected entries (sign-ins from unknown locations/devices using the correct password).
- Any Successful sign-in, Password changed, or Permission given to an application events that are not recognized.
- For activity that is not recognized:
- If it appears in the Unusual activity section, expand it and select This wasn't me.
- If it appears in the Recent activity section, expand it and select Secure your account.
- Change the password again and invalidate existing sessions
- From Security basics, select Change password and set a new, strong password that has not been used before.
- After changing the password, use the security flows (for example, via Secure your account) to sign out of other sessions where available. This helps ensure any attacker or unwanted app loses access.
- Check for signs of compromise and unusual security changes
- On the Recent activity page, review entries such as:
- Password changed
- Password reset
- Profile info changed
- Permission given to an application
- If any of these were not performed by the legitimate owner, treat the account as compromised and follow the secure-account flow from the activity entry.
- On the Recent activity page, review entries such as:
- Ensure Authenticator and device are working correctly
- Microsoft Authenticator can deny sign-ins when there is a discrepancy between GPS-reported locations; this is expected behavior when sign-in attempts come from different regions.
- If Authenticator notifications appear incorrect or approximate in location, note that the app uses the phone OS location and may show approximate addresses.
- Ensure the device time is set to automatic and correct, as Authenticator requires accurate time for notifications and approvals.
- Ignore inactive Authenticator tiles
- If Authenticator shows gray/inactive account tiles created by other apps for single sign-on, these can be safely ignored; they do not need management and are not the cause of the prompts.
If the prompts continue after changing the password and securing the account via the Recent activity flows, continue to deny them and monitor the Recent activity page for any new Unusual activity detected or Sign-in blocked entries, and respond using the built-in This wasn't me / Secure your account options.
References: