A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Microsoft does not state a threshold for “how many denied attempts” triggers an investigation. What is documented is that unusual sign-in attempts can generate email, text, or approval prompts, and unrequested prompts should be denied.
For the current situation:
- Deny any sign-in prompt that was not initiated.
- Check the Recent activity page and mark activity that was not recognized.
- If access to the account is still available, review and update security contact info on the Security basics page so alerts and verification codes go to the correct contacts.
- Turn on multifactor authentication if it is not already enabled.
- If phishing messages are involved, report them in Outlook with Report > Report phishing.
- If a suspicious Microsoft Form is being used to collect information, use the Report Abuse button on the form response page when available.
- If sign-in problems start or the account appears compromised, use the sign-in helper or Contact Microsoft Support.
On reporting: there is no general “report fraud button” for every account-access attempt described here. The documented reporting paths are specific to the content or service involved:
- Outlook or Outlook.com email: Report > Report phishing
- Teams message: More options > More actions > Report this message
- Suspicious website in Edge: Settings and More (...) > Help and feedback > Report unsafe site
- Suspicious Microsoft Form: Report Abuse on the form page
- Technical support scam or suspicious incident: use Microsoft’s scam reporting/contact path
If the concern is identity theft beyond sign-in attempts, documented guidance is to act immediately: document everything, contact affected financial institutions, place a fraud alert with a major U.S. credit bureau, close fraudulent accounts, and report identity theft to the FTC.