A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Unrequested sign-in prompts and verification codes usually mean someone is trying to access the account, or they accidentally typed the email/phone number, or a previous prompt is delayed.
To protect the account:
- Deny all unrequested prompts and codes
- In Microsoft Authenticator or Outlook mobile, always select Deny or ignore any verification code or "Are you trying to sign in?" prompt that was not initiated.
- As long as these are denied or unused, the attacker cannot complete sign-in.
- Review recent sign-in activity
- For a personal Microsoft account, go to the Security basics page and select Review activity to open the Recent activity page.
- For a work or school account, sign in to My Account, select Recent activity, and review each sign-in.
- If any activity is not recognized:
- For personal accounts: expand the event and choose This wasn’t me or Secure your account where available.
- For work/school accounts: immediately change the password and then go to the Security info page to update security settings.
- Change the password
- From the Security basics page for a personal account, select Change password and set a strong, unique password.
- For work or school accounts, use the organization’s password change process and ensure the new password is not reused elsewhere.
- Strengthen sign-in with multi-factor authentication (MFA)
- If not already enabled, register for two-step verification / MFA so that a password alone is not enough to access the account. Use the Microsoft Authenticator app where possible.
- For work or school accounts, go to the Security info page to add or confirm MFA methods.
- Consider going passwordless
- For personal accounts, enable passwordless sign-in so that sign-in uses Microsoft Authenticator, Windows Hello, physical security keys, or SMS codes instead of a password. This reduces the risk from password guessing.
- Steps (personal Microsoft account):
- Sign in to Additional security options from the Microsoft account security page.
- Under Passwordless account, select Turn on.
- Follow the prompts and approve the request in Microsoft Authenticator.
- Monitor ongoing attempts
- Continue to review Recent activity regularly. Unsuccessful attempts may indicate someone is trying to guess the password. With MFA/passwordless enabled and prompts denied, the account remains protected.
- If there are many repeated attempts or sign-in blocks for a work/school account, contact the organization’s IT administrator so they can review Microsoft Entra sign-in logs and investigate.
- Keep recovery and contact info up to date
- Ensure alternate email addresses and phone numbers on the Security basics or Security info pages are current so alerts and recovery codes reach the correct devices.
If at any point a successful sign-in appears that is not recognized, treat the account as compromised: change the password immediately, review and update security info, and follow the compromised-account recovery guidance.
References: