A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
For personal Microsoft accounts, there are built-in ways to review sign-in history and flag unusual activity, but they are accessed through specific pages rather than directly from every security email or screen.
For a personal Microsoft account:
- Review recent sign-ins and flag “this wasn’t me”
- Go to the Security basics page: https://account.microsoft.com/security
- Select Review activity. This opens the Recent activity page, which shows sign-ins for roughly the last 30 days, including location, device, and app details.
- For entries in the Unusual activity section, expand an item and select This wasn’t me.
- For entries in Recent activity, expand an item and select Secure your account if it was not you.
This is the supported way to tell Microsoft that a sign-in was not yours and to trigger the guided account‑securing flow.
- If the account was accessed by someone else
- After reviewing activity, return to the Security basics page and select Change password. Use a strong, unique password.
- If sign-in is no longer possible (for example, the attacker changed the password or security info), follow the steps in When you can't sign in to your Microsoft account and use the recovery options there.
- If you receive “unusual sign-in” alerts
- Microsoft sends alerts when sign-ins occur from new locations or devices. These alerts direct to security pages where a verification code is requested to confirm it was really the account owner.
- If unsure whether an email is legitimate, verify the sender. Legitimate unusual-activity alerts come from the Microsoft account team at ******@accountprotection.microsoft.com.
For work or school accounts (Microsoft Entra / Azure AD):
- View detailed sign-in history
- Sign in to the My Account portal: https://myaccount.microsoft.com/
- Select Recent Activity.
- Expand each sign-in to see location, browser, OS, and app details. If a sign-in is unfamiliar, change the password immediately and update security info at https://mysignins.microsoft.com/security-info.
- Interpreting sign-ins
- A successful sign-in from an unfamiliar location or device can indicate compromise; change the password and review security info.
- An unsuccessful sign-in may be a typo or an attacker guessing the password. In that case, enabling multi-factor authentication (two-step verification) is strongly recommended so a password alone is not enough to access the account.
- Searching and confirming unusual activity
- On the Review recent activity page, use the search bar (for example, search for Unsuccessful) to filter specific events.
- Sign-ins flagged as unusual can be confirmed directly in the My sign-ins page.
The sign-in history is therefore available and can be used both to review older logins (within the retention window) and to explicitly indicate that certain activity was not performed by the account owner, which then drives the remediation steps.
References: