A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Personal Microsoft account – repeated unauthorized Authenticator sign-in requests not shown in Recent Activity
I am receiving repeated unauthorized Microsoft Authenticator sign-in requests for my personal Microsoft account.
The most recent attempt occurred on 14 August 2026 at approximately 07:36 CEST (UTC+2).
Authenticator showed:
- Account:
******@dahlborg.com
Operating system: Windows
Approximate location: Herndon, United States
I was physically in Sweden
I did not initiate this sign-in and did not approve it
The request used Microsoft Authenticator number matching
I am receiving several similar requests per day.
The problem is that these authentication attempts do not appear in my Microsoft Account Recent Activity page, so I cannot see the originating IP address or determine how the authentication request was initiated.
Could you please investigate the Microsoft authentication logs for the event at approximately 2026-08-14 05:36 UTC and tell me, if available:
The source IP address / network that initiated the authentication request.
Whether this was a passwordless Authenticator sign-in request or whether the attacker successfully entered my password before MFA was triggered.
The application/service/resource the attacker was attempting to access.
Whether Microsoft recorded a device/browser/user-agent in addition to Windows.
Whether there is a request ID, correlation ID, authentication event ID, or other identifier associated with the attempt.
Why these repeated Authenticator requests are not visible in my Recent Activity page.
Whether there have been any other successful authentication stages or suspicious security events associated with these attempts.
I understand that you may not be permitted to disclose all internal telemetry. If you cannot provide the source IP, please at minimum confirm whether the correct password was presented before the Authenticator challenge or whether the challenge was initiated through Microsoft's passwordless sign-in flow.
I can provide screenshots from Microsoft Authenticator showing the unauthorized request and its timestamp/location.
Please escalate this to the team that can review Microsoft Account authentication/security logs if first-line support cannot access this information.I am receiving repeated unauthorized Microsoft Authenticator sign-in requests for my personal Microsoft account.
The most recent attempt occurred on 14 August 2026 at approximately 07:36 CEST (UTC+2).
Authenticator showed:
Account: ******@dahlborg.com
Operating system: Windows
Approximate location: Herndon, United States
I was physically in Sweden
I did not initiate this sign-in and did not approve it
The request used Microsoft Authenticator number matching
I am receiving several similar requests per day.
The problem is that these authentication attempts do not appear in my Microsoft Account Recent Activity page, so I cannot see the originating IP address or determine how the authentication request was initiated.
Could you please investigate the Microsoft authentication logs for the event at approximately 2026-08-14 05:36 UTC and tell me, if available:
The source IP address / network that initiated the authentication request.
Whether this was a passwordless Authenticator sign-in request or whether the attacker successfully entered my password before MFA was triggered.
The application/service/resource the attacker was attempting to access.
Whether Microsoft recorded a device/browser/user-agent in addition to Windows.
Whether there is a request ID, correlation ID, authentication event ID, or other identifier associated with the attempt.
Why these repeated Authenticator requests are not visible in my Recent Activity page.
Whether there have been any other successful authentication stages or suspicious security events associated with these attempts.
I understand that you may not be permitted to disclose all internal telemetry. If you cannot provide the source IP, please at minimum confirm whether the correct password was presented before the Authenticator challenge or whether the challenge was initiated through Microsoft's passwordless sign-in flow.
I can provide screenshots from Microsoft Authenticator showing the unauthorized request and its timestamp/location.
Please escalate this to the team that can review Microsoft Account authentication/security logs if first-line support cannot access this information.