A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Several concrete steps can harden the account so that repeated attack attempts stay harmless and are easier to monitor.
- Keep Microsoft Authenticator and passwordless sign-in enabled
- Authenticator is already blocking sign-ins, which is expected behavior when someone has (or is guessing) the password.
- Strengthen this by going passwordless so attackers cannot succeed with just a password:
- Sign in to your Microsoft account Additional security options and under Passwordless account, select Turn on, then approve the request in Microsoft Authenticator.
- Add multiple secure sign-in / verification methods
- Add at least one extra way to sign in or verify identity in case a device is lost:
- Go to the Advanced security options page.
- Select Add a new way to sign in or verify and add options such as another phone number, alternate email, or security key.
- Ensure all phone numbers and email addresses listed are current and under control.
- Review recent sign-in activity
- Check for any successful or suspicious sign-ins:
- Open the Recent activity page from the Microsoft account security area.
- Mark any activity that was not performed as “This wasn’t me” so Microsoft can further protect the account.
- Respond correctly to unusual sign-in alerts
- When an unusual sign-in attempt is detected, Microsoft sends email/SMS alerts and may block the sign-in.
- If a sign-in is blocked and a security code is requested, only approve or enter codes for sign-ins personally initiated.
- If traveling or using a new device, be prepared to verify with a security code from a trusted contact method.
- Maintain secure devices and sign-out hygiene
- Avoid staying signed in on public or shared computers:
- Use a private browsing window.
- Sign out when finished and close all browser windows.
- If a device is lost or not trusted anymore, use the “sign out everywhere” guidance to remove active sessions.
- Consider trusted devices for easier recovery
- Set a frequently used, secure device as a trusted device so it can be used to regain access more easily if Microsoft temporarily blocks sign-ins due to unusual activity.
With these steps in place—Authenticator/passwordless sign-in, multiple up-to-date verification methods, regular review of recent activity, and careful handling of sign-in alerts—the account remains safe even if attackers continue trying and failing to access it.
References: