Authenticator push from foreign country i did not request

Japie Teunissen 0 Reputation points
2026-05-22T20:28:09.0366667+00:00

I get authenticator app push notifications from countries brazil and thailand that i did not request myself.

My MS account.

It started a few days ago.

I ignore or deny them.

I have changed my account password. Also used the sign out everywhere option.

I’m sure i cannot log a call so what else can I do?

I do use password managers but am not aware of breaches so i guess i will have to change all passwords. Did change the one password managers master password.

Microsoft Security | Microsoft Authenticator

1 answer

Sort by: Oldest
  1. AI answer

    2026-05-22T20:28:23.5533333+00:00

    The unrequested Microsoft Authenticator prompts indicate repeated sign-in attempts to the account, often from someone entering the username and password from another location or from delayed prompts.

    Do not approve any prompts that were not initiated. Denying or ignoring them keeps the account safe because the attacker cannot complete sign-in without the correct response.

    To further secure the account:

    1. Treat the activity as an attempted compromise
      • Unrequested prompts or verification codes typically mean:
        • Someone is trying to access the account, or
        • Someone accidentally entered the account name, or
        • A previously requested prompt is delayed.
      • Continue to deny any sign-in prompts that are not initiated.
    2. Review and update security info
      • Sign in to the Microsoft account security page (for example via the paths described in the articles) and check:
        • Phone numbers
        • Alternate email addresses
        • Registered Authenticator apps and devices
      • Remove any phone, email, or device that is not recognized.
    3. Strengthen sign-in methods
      • Turn on and use strong two-step verification methods such as:
        • Microsoft Authenticator app
        • Physical security keys
        • Windows Hello
      • Consider going passwordless so that sign-in relies on Authenticator, Windows Hello, SMS/email codes, or security keys instead of a reusable password. This reduces the impact of any password leak.
    4. Keep devices and notification settings healthy
      • Ensure Authenticator notifications are working correctly so that any future prompts can be seen and denied quickly.
      • Verify the device clock is set automatically and correctly, and that notifications are allowed for Authenticator.
    5. Monitor for unusual activity
      • Regularly check the account’s recent activity and security alerts. If sign-ins from unfamiliar locations or devices appear, follow the guidance in the security pages to secure the account.

    If unrequested prompts continue after these steps, keep denying them and maintain strong, updated security info and sign-in methods. Without the correct verification response, the account remains protected.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

    1 person found this answer helpful.

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.