Someone trying to accrue Microsoft account via autenticator

Neil McMullan 25 Reputation points
2026-06-15T19:56:57.3533333+00:00

Someone is persistently trying to access my Microsoft account. I get an authenticator notification and deny, but it has happened several times in the last 36 hours and also about a month ago.

Is there anything I can do except cancel my account and create a new one?

Microsoft Security | Microsoft Authenticator
0 comments No comments

Answer accepted by question author

AI answer

2026-06-15T19:57:11.4633333+00:00

Do not cancel the account. The behavior described matches repeated, unrequested sign-in attempts, and the account is protected as long as every unexpected prompt is denied and verification codes are never approved or shared.

Actions to take:

  1. Continue denying all unrequested prompts
    • Any “Are you trying to sign in?” or Authenticator approval that was not initiated must be denied. Without the correct approval or code, the attacker cannot complete sign-in.
  2. Treat this as possible malicious activity
    • Unrequested verification prompts or codes can mean:
      1. Someone is trying to access the account.
      2. Someone mistyped the phone/email when signing in.
      3. A previously requested prompt/code is delayed.
    • Because it is persistent, assume someone may be trying to access the account and harden security.
  3. Check recent sign-in activity
    • Go to the Recent activity page for the Microsoft account to see sign-ins from the last 30 days and confirm whether any sign-ins or attempts are not recognized.
    • If anything looks unfamiliar, follow the guidance there to secure or recover a potentially compromised account.
  4. Change password and review security info
    • Change the account password to a strong, unique one.
    • Review and update security info (alternate email, phone, sign-in methods) on the Security settings/Security basics pages to ensure only trusted contact methods are listed.
  5. Consider stronger, passwordless sign-in
    • To reduce reliance on passwords (which can be guessed or phished), configure passwordless methods such as Microsoft Authenticator, Windows Hello, SMS/Email codes, or a physical security key. These require the correct response or factor at the right time and are harder for attackers to abuse.
  6. Ignore and do not respond to any unrequested codes
    • If verification codes arrive that were not requested, do not use or reply to them. Without the code, the attacker cannot proceed.
  7. If unusual activity continues
    • Keep denying prompts and monitoring Recent activity.
    • If there is evidence of access or changes not made by the account owner, follow the compromised-account guidance and, if needed, contact Microsoft Support using the official support channels referenced in the documentation.

There is no need to cancel and recreate the account if all unrequested prompts are denied, the password is changed, security info is correct, and sign-in activity is monitored.


References:

AI-generated content may be incorrect. Read our transparency notes for more information.

Was this answer helpful?

3 people found this answer helpful.

0 additional answers

Sort by: Newest

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.