Receiving Frequent Login Attempts From Outside Sources

Aaron 20 Reputation points
2026-05-21T20:49:17.68+00:00

Verify security breaches, as I am receiving numerous login attempts on my account despite multiple password changes.

Microsoft Security | Microsoft Authenticator

1 answer

Sort by: Most helpful
  1. AI answer

    2026-05-21T20:49:38.8733333+00:00

    Multiple sign-in attempts from outside sources, even after changing the password, typically indicate ongoing attack activity (such as password spray or brute-force attempts) rather than a successful breach.

    Take these steps to verify and protect the account:

    1. Review recent sign-in activity
      • For a work or school account, go to the My Account portal and open My sign-ins / Recent Activity:
        • Sign in to My Account with the work or school account.
        • Select Recent activity or My sign-ins.
        • Expand each sign-in and verify:
          • Location and IP
          • Device/OS and browser
          • Application being accessed
        • If any successful sign-in or attempt is not recognized, immediately change the password and update security info.
    2. Check for unusual or risky patterns
      • In Microsoft Entra sign-in logs (for work/school accounts), look for:
        • Many failed authentications for the account (possible password spray or brute-force).
        • Many Interrupted sign-ins with Conditional Access failures, especially where the password is correct but MFA is not completed (can indicate a compromised password blocked by MFA).
        • Smart lock-out events or frequent lockouts from unfamiliar locations.
        • Large volumes of sign-ins from many IP addresses.
      • These patterns indicate active attack attempts rather than normal user error.
    3. Use Microsoft’s protections and monitoring
      • Ensure Microsoft Entra multifactor authentication (MFA) is enabled and enforced for the account.
      • If sign-in attempts are repeatedly blocked due to unusual activity, wait for the lockout period to expire or use another MFA method to sign in.
      • If suspicious activity is confirmed, an IT administrator should:
        • Investigate Microsoft Entra sign-in logs in detail.
        • Consider enabling Microsoft Entra ID Protection to detect and mitigate risky sign-ins.
    4. If this is a personal Microsoft/Outlook.com account
      • Sign in to the Security basics page and select Review activity to open the Recent activity page.
      • Review all sign-ins and security events (successful sign-ins, security challenges, profile changes).
      • If anything suspicious is found, select This wasn’t me or Secure your account where available.
      • Change the password to a strong, unique one and ensure alternate email and phone security info are up to date.
    5. When to escalate
      • If repeated suspicious attempts continue or there is evidence of successful unauthorized access, contact the organization’s IT administrator or Help desk to:
        • Review Microsoft Entra sign-in logs.
        • Confirm whether any sign-ins were successful.
        • Adjust Conditional Access, lockout, or risk policies as needed.

    These steps verify whether there has been an actual breach and help harden the account against ongoing external login attempts.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.