A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
For repeated unexpected Microsoft Authenticator prompts and sign-in attempts from another location, the supported next steps are:
- Do not approve any unexpected Authenticator prompt. If a verification code or prompt was not requested, the account remains protected as long as it is not approved.
- Review recent sign-in activity.
- For a work or school account, use the My sign-ins page and review recent activity.
- If an entry shows “Additional verification failed, invalid code”, that means the password was accepted but MFA was not completed. In that case, changing the password is recommended and security settings should be updated.
- Use another MFA method or wait if sign-in attempts were repeated many times. Microsoft Entra multifactor authentication can temporarily block further attempts after unusual repeated sign-ins. Waiting until another attempt is allowed, or using a different MFA method, is recommended.
- Check Microsoft Authenticator notification issues on the phone. If prompts are behaving unexpectedly, verify:
- the device is not in Do Not Disturb or Quiet mode
- push notifications are enabled in device settings
- the phone has network connectivity
- the device clock is set to automatic time, then restart the device
- If this is a work or school account, contact the IT administrator. The administrator can investigate the Microsoft Entra sign-in logs to determine whether the attempts are malicious or caused by MFA configuration issues.
- If suspicious activity is confirmed, secure the account. On the recent activity/security page, use Secure your account or This wasn’t me where available, and change the password again if needed.
If the account is a personal Microsoft account, review the Recent activity page, select This wasn’t me or Secure your account for suspicious events, and change the password from the Security basics page.
References: