Someone is trying to log into my account using authentication

NATALIEE 5 Reputation points
2026-07-10T18:21:31.6866667+00:00

Hi,

long story short, I keep getting log in request through my Authenticator app that are not in the US. I always decline or if I don’t notice the notification, it just doesn’t get answered and I am assuming that then the log in request gets declined.

I have changed my password. I have removed all devices including my own having to log back in, yet I keep getting log in request.

please help. How can I get this issue resolved?

thank you!

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Newest
  1. AI answer

    2026-07-10T18:22:41.4366667+00:00

    Unrequested Microsoft Authenticator prompts mean someone is repeatedly trying to sign in with the account username, but without approval or the correct second factor, they cannot get in. Denying or ignoring the prompts keeps the account safe, but the attempts can be reduced by changing how the account can be used to sign in.

    Take these steps:

    1. Keep denying any prompts not initiated by you
      For every unexpected “Are you trying to sign in?” or number-matching prompt, always choose Deny. Unrequested prompts typically mean:
      • Someone is trying to access the account, or
      • Someone mistyped their email/phone, or
      • A delayed prompt from a past attempt.
        Without the correct response, the account remains safe.
    2. Change the sign-in email (alias) and disable sign-in on the old one
      If the current email address is known or exposed, attackers can keep triggering MFA prompts just by entering it on the sign-in page. For a personal Microsoft account:
      • Go to the Microsoft account page and add a new alias (email address) to the account.
      • Set this new alias as the primary alias (primary sign-in email).
      • Then change sign-in preferences so the old alias cannot be used to sign in anymore. It can still be used to send/receive email, but sign-in using that address will fail.
      • After this, when someone tries to sign in with the old email, they will get an error and will no longer trigger Authenticator prompts.
      This approach is described in the referenced answers as the recommended way to stop repeated unwanted sign-in attempts while keeping the account secure.
    3. Review recent activity and security settings
      • Check the account’s recent sign-in activity to confirm that no unauthorized sign-ins have succeeded.
      • If any sign-in looks unfamiliar, follow the guidance to secure the account (change password again if needed and review security info).
    4. Ensure strong password and MFA stay enabled
      • Keep a strong, unique password that is not reused on other sites.
      • Keep Microsoft Authenticator (or another MFA method) enabled; do not remove MFA, as that would reduce security.

    If this is a work or school account and the attempts continue, contact the organization’s IT/Help desk so they can review Microsoft Entra sign-in logs and, if needed, adjust aliases or apply additional protections.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.