Microsoft Authenticator: Repeated Sign-in Requests from Unknown iOS Device and Multiple Countries After Password Change

Joz Admoz 0 Reputation points
2026-05-15T23:07:16.07+00:00

Service:

Microsoft Account, Microsoft Authenticator (iOS app)

Scenario:

I have a Microsoft account that I'm actively using on Android phone and PC. Recently, I changed my Microsoft password. However, since last night, I keep receiving repeated sign-in approval requests on my Microsoft Authenticator app from an unknown iOS device. These requests are coming from different countries, and even though I deny them every time, new requests keep appearing.

Environment:

Device I use: Android phone and PC

Device making requests: Unknown iOS device (which I do NOT own)

Sign-in requests from: Multiple different countries

Password: Changed

Authenticator version: 6.2605.2973

Result/Problem:

Continuous approval requests from iOS device I don't own

Requests originating from multiple countries

Requests continue even after I deny them

Requests persist even after changing password this morning

When checking account.microsoft.com, only my PC appears in registered devices - the iOS device is NOT listed

Troubleshooting steps already taken:

✅ Changed Microsoft password this morning

✅ Checked https://account.microsoft.com - no suspicious login activity shown

✅ Checked "Recent activity" - no successful sign-ins from unknown devices

✅ Only my PC appears in registered devices list

✅ No unrecognized email recovery addresses or phone numbers registered

Questions:

Why are sign-in requests appearing from an iOS device that's not registered in my account?

How can someone attempt to sign in with requests appearing in my Authenticator if they don't have access to my new password?

Is there a way to block all sign-in requests from unknown devices?

Should I reset my password again or take additional security steps?

Additional information:

I have NOT used any iOS device on this Microsoft account

The requests appear to be automatic/repeated attempts

I have not clicked "Allow" on any of these requests

All requests have been denied/rejected

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Oldest
  1. AI answer

    2026-05-15T23:07:38.23+00:00

    The repeated prompts indicate ongoing sign-in attempts to the Microsoft account, not that an iOS device is registered or signed in successfully.

    Key points from the provided information:

    1. Why prompts appear from an unregistered iOS device
      • Sign-in prompts are triggered whenever someone enters the account’s username and password (or tries to complete a second factor) from any device or app, even if that device is not listed under registered devices.
      • The “Are you trying to sign in?” prompt can appear when:
        1. Someone is trying to access the account.
        2. Someone accidentally entered the wrong phone/email when trying to sign in.
        3. A previously requested prompt is delayed and delivered later.
      • The device list at account.microsoft.com only shows devices that have successfully signed in and registered, not every device that attempts a sign-in.
    2. How attempts can reach Authenticator after a password change
      • If someone has the correct username and is repeatedly guessing or reusing an old password, they may still be triggering security checks that cause prompts, especially if there are delayed or queued prompts.
      • The documentation explicitly states that if a prompt appears that was not initiated, it should be denied. Denying the prompt prevents the sign-in from succeeding, so the account remains safe as long as “Deny” is selected.
    3. What to do about the repeated prompts
      • Always select Deny for any sign-in request that was not initiated.
      • Review the Recent activity page regularly to confirm there are no successful sign-ins from unknown locations or devices. If any are found, follow the guidance under “If someone has accessed your account” to secure the account.
      • Ensure security contact information (email and phone) is up to date on the Security basics page so alerts and verification codes reach only trusted channels.
    4. Additional security steps
      • If there is any suspicion that the new password might be known or reused elsewhere, change the password again to a strong, unique one not used on any other site.
      • Keep denying all unrequested prompts. Without the correct response and approval, the account remains safe.
      • If unusual sign-in attempts continue, be prepared to use security codes and trusted devices as described in the “unusual sign-in” guidance to verify legitimate access.

    The behavior described (repeated prompts from different locations, no successful sign-ins, no unknown devices registered) matches the documented scenario where someone is trying to access the account but is blocked by the second factor. Denying every unrequested prompt and maintaining updated security info is the correct and sufficient response according to the provided documentation.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.