A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
The repeated prompts indicate ongoing sign-in attempts to the Microsoft account, not that an iOS device is registered or signed in successfully.
Key points from the provided information:
- Why prompts appear from an unregistered iOS device
- Sign-in prompts are triggered whenever someone enters the account’s username and password (or tries to complete a second factor) from any device or app, even if that device is not listed under registered devices.
- The “Are you trying to sign in?” prompt can appear when:
- Someone is trying to access the account.
- Someone accidentally entered the wrong phone/email when trying to sign in.
- A previously requested prompt is delayed and delivered later.
- The device list at account.microsoft.com only shows devices that have successfully signed in and registered, not every device that attempts a sign-in.
- How attempts can reach Authenticator after a password change
- If someone has the correct username and is repeatedly guessing or reusing an old password, they may still be triggering security checks that cause prompts, especially if there are delayed or queued prompts.
- The documentation explicitly states that if a prompt appears that was not initiated, it should be denied. Denying the prompt prevents the sign-in from succeeding, so the account remains safe as long as “Deny” is selected.
- What to do about the repeated prompts
- Always select Deny for any sign-in request that was not initiated.
- Review the Recent activity page regularly to confirm there are no successful sign-ins from unknown locations or devices. If any are found, follow the guidance under “If someone has accessed your account” to secure the account.
- Ensure security contact information (email and phone) is up to date on the Security basics page so alerts and verification codes reach only trusted channels.
- Additional security steps
- If there is any suspicion that the new password might be known or reused elsewhere, change the password again to a strong, unique one not used on any other site.
- Keep denying all unrequested prompts. Without the correct response and approval, the account remains safe.
- If unusual sign-in attempts continue, be prepared to use security codes and trusted devices as described in the “unusual sign-in” guidance to verify legitimate access.
The behavior described (repeated prompts from different locations, no successful sign-ins, no unknown devices registered) matches the documented scenario where someone is trying to access the account but is blocked by the second factor. Denying every unrequested prompt and maintaining updated security info is the correct and sufficient response according to the provided documentation.
References: