A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Those unexpected Microsoft Authenticator / Outlook sign-in prompts mean that something (or someone) is repeatedly trying to sign in to the Microsoft account associated with that Gmail address.
Based on the documented behavior, the causes and actions are:
- What is causing the prompts
Unrequested prompts or verification codes typically happen when:
- Someone is trying to access the account using the correct username but wrong password.
- Someone accidentally typed the email/phone when trying to sign in to their own account.
- A sign-in prompt that was legitimately triggered is being delivered with a delay.
- “Someone is trying to access your account.”
- “Someone accidentally entered the wrong phone/email when trying to sign in.”
- “Delivery of the prompt you requested some time ago was delayed.”
- Immediate safety step: always deny
The guidance is explicit:
- For unrequested prompts: always select Deny for any sign-in request that was not initiated.
- For unrequested codes: do not respond to any codes that you did not request. As long as the correct response is not provided, the attacker cannot complete sign-in and the account remains protected.
- Check recent sign-in activity for suspicious attempts
To see what is triggering these requests and from where:
- For a personal Microsoft account, go to the Recent activity page for the Microsoft account. This shows sign-ins for the last 30 days, including device/app info and locations.
- For a work/school account, sign in to My Account → Recent Activity to review sign-ins.
- Look for unfamiliar locations, devices, browsers, or apps.
- Keep in mind that mobile networks can show approximate or distant locations, so also check OS, browser, and app details.
- If any sign-in looks unfamiliar or malicious, immediately change the password and then review/update security info.
- Harden the account to reduce future attempts
Recommended actions from the documentation:
- Change the account password to a strong, unique one if this has not been done recently.
- Go to the Security settings / Security basics pages for the Microsoft account and:
- Review and update security info (phone, alternate email, Authenticator, etc.).
- Remove any security info that is not recognized.
- Consider going passwordless on the Microsoft account (using Microsoft Authenticator, Windows Hello, SMS/email codes, or security keys). Passwordless sign-in is more resistant to guessing and phishing and helps keep the account secure even if someone keeps trying the username.
- If prompts are specifically from Outlook mobile
If Outlook mobile is being used as a sign-in method and the prompts are coming from Outlook:
- Outlook mobile can be disabled as a sign-in method:
- Open Outlook mobile.
- Go to Settings → Accounts → select the account.
- Select Account → Sign-in requests.
- Turn off the toggle for Allow sign-in requests.
- This stops Outlook from being used to approve sign-ins, but does not stop attackers from attempting to sign in; it just removes that approval path.
- Outlook mobile can be disabled as a sign-in method:
- If unrequested codes/prompts continue
If repeated attempts continue over time:
- Keep denying any prompts not initiated.
- Regularly review the Recent activity page and follow the guidance there to secure the account.
- If there is evidence of successful sign-in or unusual activity, follow the “compromised account” guidance from the Recent activity and Security basics pages (change password, review devices, update security info).
These steps will not stop attackers from trying the username, but they will:
- Confirm whether there have been any successful sign-ins.
- Ensure that only trusted security methods are configured.
- Allow disabling Outlook mobile sign-in prompts if desired.
References: