Malicious Sign-in requests on Authenticator

Venkatesh Muppidi 25 Reputation points
2026-07-05T09:49:06.1966667+00:00

I keep receiving malicious sign-in requests on my Authenticator from random places across the world - Germany, Venezuela, Mauritius, etc,.

I have reviewed and removed unwanted devices, used sign-out everywhere option, and have even updated my password.

What else can I do? Please help.

Microsoft Security | Microsoft Authenticator
0 comments No comments

Answer accepted by question author
Nathan Roberts (SN) 13,616 Reputation points Student Ambassador Volunteer Moderator
2026-07-05T10:43:47.42+00:00

Hey there, Venkatesh Muppidi

I keep receiving malicious sign-in requests on my Authenticator from random places across the world - Germany, Venezuela, Mauritius, etc,.

If you keep getting requests continuously, this could mean you are a victim of a credential stuffing attack. A credential stuffing attack is is where attackers will generally use sign in information such as email addresses and passwords that have been obtained online. They generally place the email address in a bot that will constantly inject the username and passwords into the login box to try and gain access to the account.

This is why you are receiving multiple requests to sign into your account. While this doesn't mean your account has been compromised, the attacker is hoping you will accidently click yes to sign in on their request. Especially if you are trying to sign in too and are expecting a request to come through on the authenticator app.

I have reviewed and removed unwanted devices, used sign-out everywhere option, and have even updated my password.

This is a good first step to ensure your Microsoft account is kept secure. However, please be aware that changing your password doesn't stop these attempts because the bot that is behind this isn't reacting to your password change. All it is doing is running through a list of leaked passwords automatically, putting each one into the password box.

The first thing I would check is whether your email address has appeared in a known data breach using a service like “Have I Been Pwned" found here: https://haveibeenpwned.com/

If your email address, or personal information, has been in a known data breach, this can mean you are more likely to be subjected to a credential stuffing attack. However, these attacks generate countless MFA notifications constantly, so if this isn't happening, then it could be someone manually trying to gain access to your account or someone accidently trying to sign into the wrong account.

If it is a credential stuffing attack, to reduce or stop these attempts please make sure you’re using a strong unique password and keep MFA enabled as this prevents the attacker from getting in.

On a personal Microsoft account, you have the option to generate a recovery code to use for your account to use if you no longer have access to your security information and recovery methods. Please sign into your Microsoft account security page here: https://account.live.com/proofs/manage/additional

Once you have signed in, please scroll down to the bottom of the security page until you come to an option to generate a new code.

User's image

Once at the bottom, please select “Generate a new code”

You will want to keep this in a safe place. If you do get hacked, you can use this code to recover your Microsoft account. Once you generate a new code, the previous code will no longer work.

If the constant MFA prompts are disruptive, one effective option is to change your Microsoft account’s primary alias (your sign‑in email). But do not delete the old account alias. This prevents bots from continuing to trigger MFA prompts using the old sign‑in address. Changing your primary alias doesn’t delete your mailbox or emails, it only changes the address you use to sign in.

To change this on Microsoft personal accounts, please sign into your Microsoft account here: https://account.live.com/names/manage

Once you have signed into your account, you can add an email address to use when signing into your Microsoft account. You can then click onto the link to change sign in preferences and select the new email you have added and de-select the previous email.

I hope this helps,
Nathan

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

1 additional answer

Sort by: Most helpful
  1. AI answer

    2026-07-05T09:49:32.07+00:00

    Malicious sign-in prompts usually mean someone has your username and is repeatedly trying to sign in, but Microsoft Authenticator and multifactor authentication (MFA) are blocking them. Since password and device cleanup steps are already done, focus on tightening security and monitoring activity.

    1. Review recent sign-in activity and confirm what is and isn’t you
      For a work or school account:
      • Go to the My Account portal and select Recent activity.
      • Expand each sign-in and verify the location, app, operating system, and browser.
      • If anything is unfamiliar, change the password again and then go to the Security info page to review and update security methods.
      For a personal Microsoft account:
      • Go to the Security basics page and select Review activity.
      • On the Recent activity page, expand unusual items:
        • If it appears under Unusual activity, select This wasn’t me.
        • If it appears under Recent activity, select Secure your account.
      • Follow the prompts to secure the account and change the password if prompted.
    2. Treat repeated prompts as possible attack attempts
      • Repeated sign-in attempts from many locations can indicate someone is trying to guess the password.
      • MFA is doing its job by blocking access; do not approve any request that is not explicitly initiated.
    3. Ensure MFA is fully in place and security info is correct
      • For work/school accounts, register and maintain strong MFA methods on the Security info page.
      • For personal accounts, verify phone, email, and app-based methods on the Security basics page and remove any methods that are not recognized.
    4. Be aware of location inaccuracies
      • Some sign-ins may show unexpected locations because IP-based geolocation (especially on mobile networks) can be approximate.
      • Always check app, OS, and browser details in addition to location before deciding if an attempt is malicious.
    5. If attempts are very frequent or suspicious
      • For work or school accounts, contact the organization’s IT administrator and ask them to review Microsoft Entra sign-in logs for repeated attempts and to adjust conditional access or MFA policies if needed.
      • For personal accounts, continue to monitor the Recent activity page and immediately secure the account if any sign-in is successful or looks unfamiliar.

    As long as MFA is enabled and unrecognized prompts are denied, these attempts should not result in account compromise, but ongoing monitoring and keeping security info current are essential.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.