so i my account is hacked by people or bots from peru and irak

axa 0 Reputation points
2026-06-01T10:11:11.2633333+00:00

Request Id: 28b83b1e-cfc3-4b89-b401-dd8fcdbf6100

Correlation Id: 00cc49ba-035f-49d7-8298-7b82af2ea6e0

Timestamp: 2026-06-01T10:00:02Z

Message: AADSTS900561: The endpoint only accepts POST requests. Received a GET request.

Microsoft 365 and Office | Subscription, account, billing | For business | Other

1 answer

Sort by: Most helpful
  1. AI answer

    2026-06-01T10:11:35.7966667+00:00

    The error message AADSTS900561: The endpoint only accepts POST requests. Received a GET request. indicates a sign-in attempt was made incorrectly (using HTTP GET instead of POST) against a Microsoft Entra ID endpoint. This by itself does not prove compromise; it is often just a failed or malformed sign-in attempt.

    To address the concern about possible account compromise and unusual sign-ins from other countries, follow these steps:

    1. Review recent sign-in activity
      1. Go to the My Account portal and open My sign-ins:
        • Sign in with the work or school account.
      2. Select Recent Activity from the left navigation.
      3. Expand each sign-in entry and verify:
        • Location (country/region and city)
        • Browser and operating system
        • App or resource accessed
      4. If any successful sign-in is not recognized (for example, from Peru or Iraq), treat the account as compromised.
    2. If suspicious or unauthorized sign-ins are found
      1. Immediately change the account password.
      2. Go to Security info (from the same portal) and:
        • Review and update authentication methods.
        • Remove any methods that are not recognized.
      3. Sign out of all sessions if that option is available in the security settings.
    3. Use Microsoft’s hacked/compromised account guidance
      • Follow the official guidance for compromised Microsoft accounts to:
        • Secure the account.
        • Review and remediate any malicious changes.
    4. Monitor for future unusual sign-ins
      • Microsoft sends alerts (email/SMS) when unusual sign-ins occur (for example, from new locations or devices).
      • When such an alert is received, promptly review the Recent activity page and confirm whether it was legitimate.

    If the account is a personal Microsoft account (not work/school) and appears hacked, use the hacked-account recovery flow and, if needed, the Sign-in Helper tool to regain control.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.