How do I stop unknown persons trying to get into my Microsoft account.

Gareth Hector 5 Reputation points
2026-05-26T07:35:31.86+00:00

On my personal account, I have 2-Step verification, have removed password (after resetting it) forced sign out everywhere, have no devices listed but I am still getting Authenticator requests to pick a code multiple times a day.

Looks like it is "France" from an iOS device.

When I check activity I can only see successful log ins, which correlate to my own activity.

Any help please on why I'm getting these authorisation requests (which I then deny), which don't appear as unsuccessful login attempts, and what else can I do to stop these?

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Oldest
  1. AI answer

    2026-05-26T07:35:55.7633333+00:00

    Unknown sign-in prompts and Authenticator approvals usually mean someone is repeatedly trying to sign in using the correct username but without the second factor. Because they never complete the second step, these attempts may not show as successful or failed sign-ins in the normal activity list, but they still trigger “Are you trying to sign in?” prompts.

    Key points from the documented behavior:

    1. Why these prompts appear
      • Unrequested prompts can be caused by:
        1. Someone trying to access the account.
        2. Someone accidentally entering the wrong phone/email when trying to sign in.
        3. A delayed delivery of a prompt that was requested earlier.
      • The guidance is to always deny any request that was not initiated by the legitimate user. Without the correct response, the account remains safe.
    2. What to do immediately
      • Continue to select Deny on all prompts that are not initiated intentionally.
      • Check the Recent activity page and the Unusual activity section to confirm that only known sign-ins are marked as “This was me.” If anything is unfamiliar, mark it as This wasn’t me so Microsoft can help protect the account.
      • Review the account’s security info and sign-in methods on the Security basics / Security settings pages to ensure only trusted phone numbers, emails, and sign-in methods are present.
    3. Additional protections to reduce risk
      • Keep two-step verification turned on for the Microsoft account as described in the two-step verification guidance. Two-step verification ensures that even if someone knows the username and has the password removed/changed, they still cannot sign in without the second factor.
      • Consider using passwordless methods such as Microsoft Authenticator, Windows Hello, SMS/Email codes, or physical security keys, which provide stronger protection against password guessing or reuse.
      • If there is concern that someone has accessed the account or devices, follow the documented steps for compromised accounts: change security info, remove unrecognized devices, and sign out everywhere from the Security settings.
    4. Why some attempts may not show as failed sign-ins
      • The unusual activity and recent activity views focus on completed sign-ins and certain flagged events. If an attacker never completes the second factor, those attempts may surface only as prompts on the Authenticator/Outlook mobile and not as full sign-in events.
      • The recommended action remains to deny all unrequested prompts and keep security info up to date.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.