Some one trying to keep log in into my account

DD 0 Reputation points
2026-05-17T06:09:50.41+00:00

Hello,

I would like to report a security concern regarding my Microsoft account and ask for advice on how to make my account more secure.

A few days ago, I received an email containing a Microsoft one-time verification code, even though I was not trying to sign in to my account. This made me concerned that someone may have been attempting to access my account.

So, I changed my Microsoft account password , enabled 2 factor authentication using Authenticator and checked my recent sign in activity and all connected devices. There was no un-usual activities.

But, The next day, I received a notification from the Microsoft Authenticator app showing a verification code for a login attempt, even though I was not trying to sign in. I denied the request.

I would like to know:

  1. Why am I still receiving verification code requests after changing my password and enabling Microsoft Authenticator?
  2. Is this normal if someone is repeatedly trying to sign in with my email address?
  3. What additional steps can I take to make my account even more secure and prevent unauthorized access?
  4. Should I be concerned even though all login attempts were unsuccessful and no suspicious activity appears in my account?

I want to ensure that no one can gain access to my account and that my information remains secure.

Thank you for your assistance.

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-05-17T06:10:04.4833333+00:00
    1. Receiving verification prompts after changing the password and enabling Microsoft Authenticator usually means someone (or something like a saved browser/app) is still trying to sign in using the account name, but cannot proceed without the second factor. The verification code or Authenticator prompt is the protection working as designed, not a sign that the attacker has access.
    2. Yes, this can be normal if someone repeatedly types the email address as the username (whether intentionally or by mistake). As long as the password is unknown and the second factor is not approved, they cannot sign in.
    3. Additional steps to secure the account:
      • Regularly review the Recent activity for the Microsoft account to confirm there are no successful sign-ins or locations/devices that are not recognized. Use the Recent activity page linked from the Security basics page or directly via the recent activity link provided in the documentation.
      • If any activity is not recognized, expand it and choose This wasn’t me or Secure your account where available so Microsoft can help protect the account.
      • Ensure strong, unique password usage and do not reuse this password on other sites.
      • Keep alternate security info (backup email and phone) up to date so recovery options are always available.
      • Consider going further toward “passwordless” sign-in methods (for example, using Microsoft Authenticator, Windows Hello, or security keys) as described in the passwordless guidance. These methods are more resistant to password guessing and phishing.
      • Keep all devices used to access the account updated and protected with antivirus, as recommended for Outlook.com and Microsoft accounts.
    4. Concern is appropriate in the sense of staying vigilant, but if all login attempts are unsuccessful, recent activity shows no unauthorized sign-ins, and verification codes are not approved, the account remains protected by the security measures in place. The key actions are to:
      • Never approve Authenticator prompts or use verification codes that were not requested.
      • Continue monitoring recent activity and promptly report anything that was not initiated.

    If at any point it appears that someone has actually signed in (successful sign-in from an unknown device or location), follow the compromised-account guidance: review recent activity, mark unfamiliar activity as not yours, change the password again from a clean device, and verify all security info and sign-in methods.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.