Constant unauthorized sign in attempts are really annoying… clear data leak

Emily Isaac 0 Reputation points
2026-08-15T15:21:43.0133333+00:00

I have been getting constant push notifications to authorize sign in attempts… obviously I’m not going to do so but it’s getting really annoying. Once or twice every few hours. Obviously this indicates some sort of data leak… it’s so annoying, I’m about to delete both my Microsoft account and the Authenticator app. This happened a couple months ago so yes, I changed my password. I don’t want to do this every time YOUR security gets breached . Can you guys start like, blocking IPs or something?

Microsoft Security | Microsoft Authenticator

1 answer

Sort by: Newest
  1. AI answer

    2026-08-15T15:22:00.98+00:00

    Those prompts do not mean the account was signed in to. They usually mean someone is trying to sign in, someone entered the wrong phone or email, or a delayed prompt arrived. For any prompt not initiated by the account owner, select Deny.

    For a personal Microsoft account, the supported actions are:

    1. Go to the Security basics page.
    2. Select Review activity and check the Recent activity page for unusual sign-in attempts.
    3. If any activity is clearly not recognized, select This wasn't me for unusual activity entries, or Secure your account for recent activity entries.
    4. From Security basics, select Change password and use a strong password.

    If repeated prompts continue even after a password change, accepted Microsoft Q&A guidance in this scenario is to reduce sign-in attempts against an exposed sign-in name by:

    1. Adding a new email alias to the Microsoft account.
    2. Making the new alias the primary alias.
    3. Disabling sign-in for the old alias while keeping it for email use.

    That prevents the old exposed alias from being used to sign in, which can stop repeated unsolicited Authenticator prompts.

    If the issue is with Authenticator notifications themselves:

    1. Check that the phone is not in Do Not Disturb or Quiet mode.
    2. If notifications fail for only one account, remove that account from Authenticator and add it again, allowing notifications.
    3. If prompted with Enable push notifications to receive alerts, enable push notifications in device settings and confirm network connectivity.

    For a work or school account:

    1. Sign in to My Account.
    2. Open Recent Activity from the left pane and review sign-ins.
    3. If a successful sign-in is not recognized, immediately change the password.
    4. Go to Security info to update security settings.
    5. If many sign-in attempts triggered MFA protection, wait and try again later or use a different MFA method. If someone else may be trying to access the account, contact the IT administrator.

    Microsoft Entra documentation also notes that anomalous sign-ins do not generate push notifications automatically. To approve an anomalous sign-in, the user must open Microsoft Authenticator or Authenticator Lite and refresh manually.


    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.