For several days I have been receiving repeated sign-in prompts in the Microsoft Authenticator app for my Microsoft account. The prompts indicate a Windows sign-in attempt and only show my account email, “Windows” as the platform, and “Germany” as the origin.
This does not make sense in my case: I do not use Windows with a Microsoft account and have no Windows machine running during this time and I have not initiated any sign-ins during these times. Therefore, it looks like someone may be attempting to compromise my account or is repeatedly triggering sign-in prompts.
What I have already done:
Changed my password → prompts still continue.
Switched the account to passwordless → prompts still continue.
Checked the Microsoft Account Security Center → I see no active sessions from unknown devices and no sign-in attempts that correspond to these Authenticator push prompts.
Questions / Issue:
What exactly are these Authenticator sign-in prompts, if there are no corresponding sign-in attempts visible in the Security Center?
Why are no useful details shown (at least IP address, more precise location, client/app details), and only “Windows” and “Germany”?
How can I stop these prompts completely, unless they are initiated by me?
If these are real attack attempts: How can I identify the source (at least the IP address) so I can take further action, potentially legal (police report against unknown person).
Additional notes:
These are not accidental sign-ins from my own Windows devices; I do not sign in to Windows with this Microsoft account.
I want to prevent “MFA fatigue” style pressure from repeated prompts.
What I’m looking for from Support:
An explanation of how these push prompts can occur without corresponding entries in Security Center,
clear steps to fully prevent or block them,
- and whether Microsoft provides more detailed audit/log information (including IP/client details), or can provide it upon request.