Why is Microsoft the only tech giant that refuses to filter out obvious out-of-region login attacks?

Raul Torres 0 Reputation points
2026-07-05T19:49:46.3+00:00

I understand the logistical and financial realit… implementing custom security features for a relatively small percentage of users experiencing daily credential stuffing might not look profitable on a corporate balance sheet. But this is seriously the ONLY tech giant that I know of that has had this ongoing problem for so many years now and still offers the same scripted troubleshooting guide that does nothing to make it stop.

Microsoft already tracks our primary locations, residences, and frequent addresses across a massive ecosystem of services. So then I ask, Microsoft, since you already know our location and where we reside, or any addresses saved and frequented through the myriad services you maintain... why can't it be possible to simply IGNORE OR suppress any and all requests that are Obviously stemming from locations we're clearly not present in?

Right now, malicious actors use commercial VPNs to spoof locations, and your credential access somehow allows or recognizes those attempts as legit as they undergo more legitimate verification steps that identify the login user as the true account user. This forces legitimate account owners to constantly deal with secondary verification prompts and security alerts for traffic that should have been blocked at the border.

Can Microsoft get feedback from these forums or is this a lost cause? Because I've submitted and are still willing to submit this same post on any feedback channels they have as long as it's one they not only read but direct to the right team. So far it seems suggestions just go into the furnace to generate heat. That's right. That was a reference to The Oblongs.

Microsoft Security | Microsoft Authenticator
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.