A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Unknown sign-in prompts and Authenticator approvals usually mean someone is repeatedly trying to sign in using the correct username but without the second factor. Because they never complete the second step, these attempts may not show as successful or failed sign-ins in the normal activity list, but they still trigger “Are you trying to sign in?” prompts.
Key points from the documented behavior:
- Why these prompts appear
- Unrequested prompts can be caused by:
- Someone trying to access the account.
- Someone accidentally entering the wrong phone/email when trying to sign in.
- A delayed delivery of a prompt that was requested earlier.
- The guidance is to always deny any request that was not initiated by the legitimate user. Without the correct response, the account remains safe.
- Unrequested prompts can be caused by:
- What to do immediately
- Continue to select Deny on all prompts that are not initiated intentionally.
- Check the Recent activity page and the Unusual activity section to confirm that only known sign-ins are marked as “This was me.” If anything is unfamiliar, mark it as This wasn’t me so Microsoft can help protect the account.
- Review the account’s security info and sign-in methods on the Security basics / Security settings pages to ensure only trusted phone numbers, emails, and sign-in methods are present.
- Additional protections to reduce risk
- Keep two-step verification turned on for the Microsoft account as described in the two-step verification guidance. Two-step verification ensures that even if someone knows the username and has the password removed/changed, they still cannot sign in without the second factor.
- Consider using passwordless methods such as Microsoft Authenticator, Windows Hello, SMS/Email codes, or physical security keys, which provide stronger protection against password guessing or reuse.
- If there is concern that someone has accessed the account or devices, follow the documented steps for compromised accounts: change security info, remove unrecognized devices, and sign out everywhere from the Security settings.
- Why some attempts may not show as failed sign-ins
- The unusual activity and recent activity views focus on completed sign-ins and certain flagged events. If an attacker never completes the second factor, those attempts may surface only as prompts on the Authenticator/Outlook mobile and not as full sign-in events.
- The recommended action remains to deny all unrequested prompts and keep security info up to date.
References:
- Using Outlook mobile to sign in
- Troubleshoot Microsoft verification code issues
- Why is Microsoft texting me?
- What happens if there's an unusual sign-in to your account
- Check the recent sign-in activity for your Microsoft account
- What is the Recent activity page?
- How to use two-step verification with your Microsoft account