A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
"Successful Sign-in" followed by "Unusual Activity Detected" log
Hi Microsoft Experts,I recently checked my Microsoft account's Recent Activity and noticed something confusing. At the bottom of the log, there was a "Successful sign-in" from an unfamiliar IP address. Immediately above that entry,the session activity of it say "unusual activity resolved", at the exact same time, the system flagged "Unusual activity detected.",and the session activity of it only said " unusual activity detected" My account did not have 2FA enabled at that moment.I would like to clarify the exact technical scenario of this event:Does "Successful sign-in" here simply mean the attacker guessed my password correctly and enter my account succesfully because i dont have 2FA, but was immediately blocked/kicked by the AI because of the strange IP (which generated the "Unusual activity" flag above it)?Or is it possible that the attacker used stolen session cookies to bypass authentication, causing this specific sequence of logs?