A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Do not approve any of those prompts. As long as the number in Microsoft Authenticator is not approved, the attacker cannot complete sign-in.
To reduce or stop these attempts and better protect the account:
- Change the account password immediately
- Use a strong, unique password that is not used on any other site.
- This helps if the attacker is using an old or leaked password.
- Review recent sign-in activity
- Go to the Microsoft account Recent activity page.
- Mark any sign-ins that are not recognized as “This wasn’t me” and follow the prompts to secure the account.
- Check security info and remove anything suspicious
- On the Security basics page, verify phone numbers, email addresses, and sign-in methods.
- Remove any phone, email, or sign-in method that is not recognized.
- Stay alert to unrequested codes and prompts
- If verification codes or Authenticator prompts appear without trying to sign in, treat it as someone trying to access the account.
- Do not read codes to anyone or approve any prompt that was not initiated.
- Consider going passwordless
- Use Microsoft Authenticator, Windows Hello, or security keys as primary sign-in methods.
- Passwordless sign-in reduces the risk from password guessing and phishing.
- If attempts are very frequent or suspicious
- Run security checks on devices (antivirus, OS updates).
- If this is a work or school account, contact the organization’s IT/Help desk and ask them to review Microsoft Entra sign-in logs for malicious activity.
The key protection is to never approve a sign-in request that was not initiated. Without that approval or code, the account remains safe even if someone keeps trying.
References: