A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Do not cancel the account. The behavior described matches repeated, unrequested sign-in attempts, and the account is protected as long as every unexpected prompt is denied and verification codes are never approved or shared.
Actions to take:
- Continue denying all unrequested prompts
- Any “Are you trying to sign in?” or Authenticator approval that was not initiated must be denied. Without the correct approval or code, the attacker cannot complete sign-in.
- Treat this as possible malicious activity
- Unrequested verification prompts or codes can mean:
- Someone is trying to access the account.
- Someone mistyped the phone/email when signing in.
- A previously requested prompt/code is delayed.
- Because it is persistent, assume someone may be trying to access the account and harden security.
- Unrequested verification prompts or codes can mean:
- Check recent sign-in activity
- Go to the Recent activity page for the Microsoft account to see sign-ins from the last 30 days and confirm whether any sign-ins or attempts are not recognized.
- If anything looks unfamiliar, follow the guidance there to secure or recover a potentially compromised account.
- Change password and review security info
- Change the account password to a strong, unique one.
- Review and update security info (alternate email, phone, sign-in methods) on the Security settings/Security basics pages to ensure only trusted contact methods are listed.
- Consider stronger, passwordless sign-in
- To reduce reliance on passwords (which can be guessed or phished), configure passwordless methods such as Microsoft Authenticator, Windows Hello, SMS/Email codes, or a physical security key. These require the correct response or factor at the right time and are harder for attackers to abuse.
- Ignore and do not respond to any unrequested codes
- If verification codes arrive that were not requested, do not use or reply to them. Without the code, the attacker cannot proceed.
- If unusual activity continues
- Keep denying prompts and monitoring Recent activity.
- If there is evidence of access or changes not made by the account owner, follow the compromised-account guidance and, if needed, contact Microsoft Support using the official support channels referenced in the documentation.
There is no need to cancel and recreate the account if all unrequested prompts are denied, the password is changed, security info is correct, and sign-in activity is monitored.
References:
- Using Outlook mobile to sign in
- Why is Microsoft texting me?
- Common problems with two-step verification for a work or school account
- Can I trust email from the Microsoft account team?
- Check the recent sign-in activity for your Microsoft account
- What happens if there's an unusual sign-in to your account