A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
- Receiving verification prompts after changing the password and enabling Microsoft Authenticator usually means someone (or something like a saved browser/app) is still trying to sign in using the account name, but cannot proceed without the second factor. The verification code or Authenticator prompt is the protection working as designed, not a sign that the attacker has access.
- Yes, this can be normal if someone repeatedly types the email address as the username (whether intentionally or by mistake). As long as the password is unknown and the second factor is not approved, they cannot sign in.
- Additional steps to secure the account:
- Regularly review the Recent activity for the Microsoft account to confirm there are no successful sign-ins or locations/devices that are not recognized. Use the Recent activity page linked from the Security basics page or directly via the recent activity link provided in the documentation.
- If any activity is not recognized, expand it and choose This wasn’t me or Secure your account where available so Microsoft can help protect the account.
- Ensure strong, unique password usage and do not reuse this password on other sites.
- Keep alternate security info (backup email and phone) up to date so recovery options are always available.
- Consider going further toward “passwordless” sign-in methods (for example, using Microsoft Authenticator, Windows Hello, or security keys) as described in the passwordless guidance. These methods are more resistant to password guessing and phishing.
- Keep all devices used to access the account updated and protected with antivirus, as recommended for Outlook.com and Microsoft accounts.
- Concern is appropriate in the sense of staying vigilant, but if all login attempts are unsuccessful, recent activity shows no unauthorized sign-ins, and verification codes are not approved, the account remains protected by the security measures in place. The key actions are to:
- Never approve Authenticator prompts or use verification codes that were not requested.
- Continue monitoring recent activity and promptly report anything that was not initiated.
If at any point it appears that someone has actually signed in (successful sign-in from an unknown device or location), follow the compromised-account guidance: review recent activity, mark unfamiliar activity as not yours, change the password again from a clean device, and verify all security info and sign-in methods.
References: