A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
To stop repeated Microsoft Authenticator prompts from different locations while keeping the account secure, take these steps:
- Review recent sign-in activity
- Go to the Security basics page: https://account.microsoft.com/security
- Select Review activity to open the Recent activity page.
- Look for sign-in attempts from unfamiliar locations or devices.
- For any activity that is not recognized:
- If it appears under Unusual activity, expand it and select This wasn't me.
- If it appears under Recent activity, expand it and select Secure your account.
- This helps Microsoft flag those attempts as malicious and can adjust protections accordingly.
- Change the account password
- From the Security basics page, select Change password.
- Set a strong, unique password that is not reused on other sites.
- This reduces the chance that attackers are using a known or reused password to trigger MFA prompts.
- Ensure security info is up to date
- On the Security basics page, verify alternate email addresses and phone numbers.
- Remove any contact methods that are not recognized and add trusted ones so account recovery remains under control.
- Keep MFA enabled everywhere possible
- Multifactor authentication is blocking these sign-in attempts as designed.
- MFA typically only prompts on new apps/devices or after password changes; persistent prompts usually indicate repeated attack attempts from other devices.
- Continue denying any prompts that are not initiated personally.
- Check devices and apps
- Ensure all devices used to sign in are secure and updated.
- Run antivirus scans and keep operating systems up to date, as compromised devices can leak credentials.
If the prompts continue at a high frequency even after changing the password and reviewing activity, repeat the Review activity and Change password steps and monitor for any new suspicious sign-ins.
References: