A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Repeated Authenticator prompts mean someone is repeatedly trying to sign in, not that they already have access.
Microsoft Entra multifactor authentication detects unusual activity like repeated sign-in attempts and may block additional attempts to counter security threats. When an attacker has only the username and password but not the second factor, they will keep triggering MFA prompts that can be denied. This is expected behavior and indicates that multifactor authentication is protecting the account.
To reduce risk and secure the account further:
- Keep denying any sign-in attempts that are not initiated personally.
- Review recent sign-in activity and security info on the Microsoft account Security basics page and remove any phone numbers, emails, or devices that are not recognized.
- Ensure multifactor authentication remains enabled on the account and that Microsoft Authenticator is installed and working correctly.
- If there is any suspicion that someone else might be trying to access a work or school account, contact the organization’s IT administrator and have them review Microsoft Entra sign-in logs for malicious activity or misconfigured MFA settings.
If sign-in attempts have been made too many times, Microsoft Entra multifactor authentication may temporarily prevent additional attempts. In that case, wait and try again later or use a different MFA method.
These prompts do not by themselves mean the attacker has full access; they indicate that the second factor is blocking them.
References: