A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Those calls are almost certainly not legitimate Microsoft sign-in calls and should be treated as suspicious.
Key points and actions:
- Microsoft will not proactively call to provide unsolicited technical support or to verify sign-in activity. Any unexpected call claiming to be from Microsoft should be treated as untrusted.
- Do not answer, follow any prompts, or provide any personal information (codes, passwords, or account details) over these calls.
- If unsure whether any sign-in activity is real, do not use links or phone numbers from the call. Instead, independently go to https://account.microsoft.com or https://account.live.com in a browser and review recent sign-in activity and security settings there.
- If any verification codes or security prompts are received that were not initiated, this can mean someone is trying to access the account or has mistyped a phone/email. Follow the guidance in the verification-code troubleshooting article to help keep the account secure and avoid repeated requests.
- Treat this as a potential tech support/impersonation scam. Report it to Microsoft as a scam attempt and, if needed, to local authorities:
- Use https://www.microsoft.com/reportascam to report tech support scams.
- In Microsoft Edge, suspicious sites can be reported via Settings and more > Help and feedback > Report unsafe site.
- If any device or account compromise is suspected, immediately sign in via the official account portal, change the password, review security info (phone, email, sign-in methods), and enable two-step verification using trusted methods (such as Microsoft Authenticator) as described in the security guidance.
References: