A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
To reduce or stop these continuous sign-in requests and ensure the account is secure, follow these steps:
- Review recent sign-in activity
- Go to the Recent activity page for the Microsoft account.
- Check all entries from the last 30 days, especially those from unfamiliar countries or devices.
- For any activity that is not recognized, expand it and mark it as suspicious:
- If it appears under Unusual activity, select This wasn't me.
- If it appears under Recent activity, select Secure your account.
- Secure the account if there is any sign of compromise
- Go to the Security basics page and select Change password.
- Set a strong, unique password that is not reused on other sites.
- After changing the password, review and update all security info (phone numbers, alternate emails) to ensure they belong only to the legitimate owner.
- Respond properly to unusual sign-in alerts
- When Microsoft detects sign-in attempts from new locations or devices, it sends email and SMS alerts to the alternate contact methods.
- Only approve sign-in requests that are clearly initiated by the legitimate user.
- If an alert is received but no sign-in was attempted, treat it as suspicious and review activity as above.
- Handle “unusual activity” and temporary blocks
- If frequent attempts or patterns look risky, Microsoft may temporarily block certain verification methods or sign-ins and show messages like “Try another verification method.”
- In that case:
- Try another verification method already configured (for example, alternate email instead of SMS).
- Try another network (switch between Wi‑Fi and cellular, or use a different Wi‑Fi network).
- Avoid repeated attempts in a short time; if blocked, wait at least 24 hours, and up to a week if needed, for automatic resolution.
- Ongoing protection
- Keep security info up to date on the Security basics page so alerts and verification codes always reach valid contact methods.
- Never approve sign-in notifications that are not clearly initiated by the legitimate user.
- Periodically re-check Recent activity and security settings to ensure no unexpected changes.
These steps help both to stop attackers from successfully signing in and to reduce persistent, suspicious sign-in attempts being treated as legitimate.
References: