A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Yes. The practical way to investigate is to review recent sign-in activity for the account and look for failed or unusual attempts.
For a Microsoft account:
- Go to the Recent activity page.
- Review sign-ins from the last 30 days, including device or app details.
- If anything looks unfamiliar, change the password and update security settings.
For a work or school account:
- Sign in to My Account.
- Select Recent Activity.
- Expand each sign-in item and review the location, browser, operating system, and app.
- If a sign-in is unfamiliar, change the password and update Security info.
What the Authenticator prompts usually mean:
- Someone may be trying to access the account.
- Someone may have entered the wrong phone number or email by mistake.
- A previously requested prompt may have been delayed.
What can and cannot be identified:
- The sign-in history can show details such as location, app, operating system, browser, and whether the attempt was successful or unsuccessful.
- It does not provide a direct identity of the person making the request.
Important actions:
- Deny any Authenticator prompt that was not initiated.
- If recent activity shows successful primary sign-in followed by failed additional verification, change the password immediately.
- If repeated prompts continue, review security settings and consider stronger sign-in methods such as multi-factor authentication or passwordless options where available.
References: