A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Multiple sign-in attempts from outside sources, even after changing the password, typically indicate ongoing attack activity (such as password spray or brute-force attempts) rather than a successful breach.
Take these steps to verify and protect the account:
- Review recent sign-in activity
- For a work or school account, go to the My Account portal and open My sign-ins / Recent Activity:
- Sign in to My Account with the work or school account.
- Select Recent activity or My sign-ins.
- Expand each sign-in and verify:
- Location and IP
- Device/OS and browser
- Application being accessed
- If any successful sign-in or attempt is not recognized, immediately change the password and update security info.
- For a work or school account, go to the My Account portal and open My sign-ins / Recent Activity:
- Check for unusual or risky patterns
- In Microsoft Entra sign-in logs (for work/school accounts), look for:
- Many failed authentications for the account (possible password spray or brute-force).
- Many Interrupted sign-ins with Conditional Access failures, especially where the password is correct but MFA is not completed (can indicate a compromised password blocked by MFA).
- Smart lock-out events or frequent lockouts from unfamiliar locations.
- Large volumes of sign-ins from many IP addresses.
- These patterns indicate active attack attempts rather than normal user error.
- In Microsoft Entra sign-in logs (for work/school accounts), look for:
- Use Microsoft’s protections and monitoring
- Ensure Microsoft Entra multifactor authentication (MFA) is enabled and enforced for the account.
- If sign-in attempts are repeatedly blocked due to unusual activity, wait for the lockout period to expire or use another MFA method to sign in.
- If suspicious activity is confirmed, an IT administrator should:
- Investigate Microsoft Entra sign-in logs in detail.
- Consider enabling Microsoft Entra ID Protection to detect and mitigate risky sign-ins.
- If this is a personal Microsoft/Outlook.com account
- Sign in to the Security basics page and select Review activity to open the Recent activity page.
- Review all sign-ins and security events (successful sign-ins, security challenges, profile changes).
- If anything suspicious is found, select This wasn’t me or Secure your account where available.
- Change the password to a strong, unique one and ensure alternate email and phone security info are up to date.
- When to escalate
- If repeated suspicious attempts continue or there is evidence of successful unauthorized access, contact the organization’s IT administrator or Help desk to:
- Review Microsoft Entra sign-in logs.
- Confirm whether any sign-ins were successful.
- Adjust Conditional Access, lockout, or risk policies as needed.
- If repeated suspicious attempts continue or there is evidence of successful unauthorized access, contact the organization’s IT administrator or Help desk to:
These steps verify whether there has been an actual breach and help harden the account against ongoing external login attempts.
References:
- Common problems with two-step verification for a work or school account
- View your work or school account sign-in activity from My Sign-ins
- What happens if there's an unusual sign-in to your account
- What is the Recent activity page?
- Help protect your Outlook.com email account
- Microsoft Entra security operations for user accounts