Microsoft Authenticator keeps showing repeated sign-in approval requests

Arne Meier 0 Reputation points
2026-05-25T12:25:45.7833333+00:00

Microsoft Authenticator keeps showing repeated sign-in approval requests on my phone. The prompts indicate a Windows sign-in attempt, but:

• I have already changed my password. • MFA/Authenticator is enabled. • The sign-in attempts continue. • The attempts do not appear in my Microsoft account's sign-in activity/history. • I don't see any unknown devices associated with my account.

From what I understand, these could be:

Sign-in attempts that are blocked very early by Microsoft's security systems and therefore never appear in the user-visible sign-in logs.

MFA push-spam ("MFA fatigue") attempts.

A stale token or an old device/service repeatedly trying to authenticate.

What I find particularly concerning is that Microsoft provides no clear way to identify exactly what device is generating these requests. Support has not been able to tell me which device is attempting to sign in, and the sign-in history does not provide enough detail to investigate properly.

In 2026, I find it quite surprising that account owners cannot easily see the source IP address, device identifier, or other technical details associated with these authentication attempts. If Microsoft expects users to secure their accounts, there should be better tools available to identify and stop suspicious authentication activity.

Has anyone experienced this before? Is there another Microsoft log or audit location that shows the source of Authenticator prompts that are not visible in the standard sign-in history?

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-05-25T12:26:07.0033333+00:00

    Repeated Microsoft Authenticator prompts that do not show up in the visible sign-in history are consistent with:

    • Early-blocked or anomalous sign-in attempts that are filtered by Microsoft’s risk engine before they become normal, user-visible sign-ins.
    • MFA push notifications generated by an existing sign-in flow (for example, a stale token or background client) that is being challenged but never fully completes.

    For consumer Microsoft accounts, there is no additional Microsoft-provided log beyond the standard Recent activity / Unusual activity views that exposes raw IP, device identifiers, or all pre-blocked attempts. The available tools are limited to:

    1. Reviewing unusual activity and securing the account
      • Go to the Security basics page and use Review activity to inspect the Recent activity page.
      • For anything suspicious that does appear, mark it as This wasn’t me (under Unusual activity) or use Secure your account (under Recent activity) so Microsoft can help lock down the account and adjust risk signals.
      • If there is any chance the account was accessed, change the password again from the Security basics page and ensure all security info (phone, alternate email) is up to date.
    2. Handling unrequested prompts in Authenticator / Outlook mobile
      • For any prompt that was not initiated, always select Deny. This protects the account even if someone has the correct password.
      • Outlook mobile and Authenticator can show “Are you trying to sign in?” prompts for:
        • Someone actively trying to access the account.
        • Someone mistyping an email/phone.
        • Delayed delivery of a previously requested prompt.
      • Denying these prompts is sufficient to keep the account safe as long as the approval is never granted.
    3. Dealing with blocks and repeated attempts
      • Microsoft Entra multifactor authentication (for work/school accounts) can temporarily block sign-ins after repeated attempts or unusual activity. In those cases, the guidance is to:
        • Wait for the block window to expire, or
        • Use a different MFA method if available.
      • For consumer accounts, similar risk-based blocks can result in messages like “Try another verification method” and some attempts never surfacing in user-facing logs.
    4. Limitations on visibility
      • For consumer Microsoft accounts, there is no documented additional log or portal that exposes:
        • All pre-blocked or anomalous sign-in attempts that never become full sign-ins.
        • The raw IP address or device identifier behind each Authenticator prompt.
      • The Recent activity and Unusual activity views, plus email/SMS alerts from ******@accountprotection.microsoft.com, are the only supported visibility points.
    5. Practical mitigation steps
      • Continue to deny all unrequested prompts.
      • Ensure the device clock is correct and notifications are working properly so prompts are timely and not delayed (which can make them look suspicious).
      • If using a work/school account, ask an IT administrator to review Microsoft Entra sign-in logs for more detailed information; those logs can show IPs, locations, and client details, but are not available for personal accounts.

    If the prompts persist despite password changes and careful denial of all unrequested approvals, the behavior is still handled by Microsoft’s risk and MFA systems, but there is no additional Microsoft log or audit location for consumer accounts beyond what is already exposed in the standard sign-in and activity views.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.