Authenticator is blocking hackers but how do I make sure my account is safe since it is being attacked?

clif darnell 0 Reputation points
2026-05-18T23:32:47.71+00:00

On two occasions now I’ve had the Authenticator pop up when I have not used my account. Obviously it is doing its job by preventing access to my account but if someone is actively attempting to hack my account I feel like I need to take steps to insure this doesn’t happen. I assumed this would be something Microsoft support would help with and I wouldn’t be making an faq post?

Microsoft Security | Microsoft Authenticator

1 answer

Sort by: Oldest
  1. AI answer

    2026-05-18T23:33:03.2833333+00:00

    Several concrete steps can harden the account so that repeated attack attempts stay harmless and are easier to monitor.

    1. Keep Microsoft Authenticator and passwordless sign-in enabled
    • Authenticator is already blocking sign-ins, which is expected behavior when someone has (or is guessing) the password.
    • Strengthen this by going passwordless so attackers cannot succeed with just a password:
      • Sign in to your Microsoft account Additional security options and under Passwordless account, select Turn on, then approve the request in Microsoft Authenticator.
    1. Add multiple secure sign-in / verification methods
    • Add at least one extra way to sign in or verify identity in case a device is lost:
      • Go to the Advanced security options page.
      • Select Add a new way to sign in or verify and add options such as another phone number, alternate email, or security key.
    • Ensure all phone numbers and email addresses listed are current and under control.
    1. Review recent sign-in activity
    • Check for any successful or suspicious sign-ins:
      • Open the Recent activity page from the Microsoft account security area.
      • Mark any activity that was not performed as “This wasn’t me” so Microsoft can further protect the account.
    1. Respond correctly to unusual sign-in alerts
    • When an unusual sign-in attempt is detected, Microsoft sends email/SMS alerts and may block the sign-in.
    • If a sign-in is blocked and a security code is requested, only approve or enter codes for sign-ins personally initiated.
    • If traveling or using a new device, be prepared to verify with a security code from a trusted contact method.
    1. Maintain secure devices and sign-out hygiene
    • Avoid staying signed in on public or shared computers:
      • Use a private browsing window.
      • Sign out when finished and close all browser windows.
    • If a device is lost or not trusted anymore, use the “sign out everywhere” guidance to remove active sessions.
    1. Consider trusted devices for easier recovery
    • Set a frequently used, secure device as a trusted device so it can be used to regain access more easily if Microsoft temporarily blocks sign-ins due to unusual activity.

    With these steps in place—Authenticator/passwordless sign-in, multiple up-to-date verification methods, regular review of recent activity, and careful handling of sign-in alerts—the account remains safe even if attackers continue trying and failing to access it.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.