A tool for managing user identities, credentials, and access across on-premises and cloud environments
Following - same scenario with me. Based in US, successful sign in in Phoenix.
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
This afternoon I noticed a successful sign in on my Microsoft account from an IPv6 address. I am located in the US, so this is abnormal. The address is 2a01:111:f402:f0f9::f147. The location shows as Phoenix, Arizona.
Upon looking into the address, the signs point to it being a Microsoft Data Center. I reset my password anyway just out of caution.
I already had MFA enabled, my password was reset two weeks prior to this for unrelated reasons, and I never received a login notification after this event. There are no unknown devices or apps connected to my account.
I did update and shutdown my PC around 10-30 minutes before the login appeared on my account. Could this be from a Microsoft service accessing my account?
A tool for managing user identities, credentials, and access across on-premises and cloud environments
I am getting the same, but from a Microsoft datacenter in Canada. Changed my password after the first time I saw it, but this morning saw another login. I use 2fa using authenticator.
I (based in the US) received the same strange sign-in notification with a similar IP address about 11 hours ago. I also use MS Autheticator to sign in but got no Authenticator notification.
Same thing happened to me. An IPv6 account login successfully 2 days ago from the US (I’m based in Indonesia). My account is passwordless and there is no notification of this login activity on my MS Authenticator app. I forced logout from all devices just to be safe.
Same thing here, guys! I changed my password twice, enabled 2fA, disconnected all active sessions and yet there was this strange sucessful sign in on my account just a few hours ago.
What really intrigues me is that, besides the sucessful log in, there was no activity on my account whatsoever. No password change, nothing! Just the log in.
The first log in was on 24/07, then on 28/07 and lastly on 31/07 (today).
O mais esquisito nisso tudo é que não teve nenhuma alteração na minha conta. Só um login suspeito e mais nada. Eu tava muito tenso de início, mas fiquei tranquilo ao saber que não fui o único.
Yep, me too. Always used 2factor, reset password, signed out of everything, reset backup code.
Mine is coming from Japan every time, basically once a day.
I too have received two logins yesterday, both with a IPv6 address and both pointing to a Microsoft Data centre near Washington (I'm in the UK). I had 2FA and Authenticator but no notifications which is weird as when I went through the process everyone has it gave me loads of warnings things were being changed when I changed them. I wonder if it is some bug.
A little same to me. I am from Germany and it’s showing me probably the same data center. This may make sense because we are both from Europe and this may be the nearest datacenter.
Have the same issue in California. IPv6 successful sign in attempt, Authenticator showing Des Moines, Iowa using Password less and sign-in notification.
3rd time since July 25
Same issue for me.
Device/platform Unknown
Browser/app Unknown
IP address 2a01:111:f402:f154::f140
location: Montreal
is this an issue on Microsoft side?
Same issue for me, have we received any update from Microsoft for this problem?
I'm in Australia, and I've received the same alert from Canada with the address 2a01:111:f402:f078::f164
I was passwordless for as long as it was publicly GA, but out of caution I clicked "Secure account" underneath this successful but suspicious login attempt - I got two prompts in Authenticator this same morning, hence the alarm - and the security dashboard asked me to set a password?!
Now finding this thread, I'm starting to wonder if the seemingly random authentication requests I was getting in Authenticator were this same data center. Since the failed recent attempts appears to have been removed from the security dashboard, I can't see from where they were coming so it's hard to know if it was any of my devices. I checked them all, and all seemed to be able to fetch email from outlook.com at least.
I am glad to see that I am not the only one affected.
No mail notification due to login from a new device.
I asked the same question on reddit a few days ago:
https://www.reddit.com/r/Passwords/comments/1m9vr5n/microsoft_live_account_successful_login_despite/
I also chatted with Microsoft support, but they did not answer my question if these ip adresses really belong to Microsoft.
I would be shocked if this was NOT a Microsoft login, given how many others are experiencing the same issue.
I inquired with MS's Ai Co-Pilot. Basically, it said it is probably part of MS's maintenance ... but I've never seen anything like it before. Co-Pilot did say I can change my password, etc. However, I did not change anything, and I still have control of my account, which would be unusual if it were a hacker. It stinks that MS has not seen fit to tell us what happened, but it is probably a nothing burger. One that will forever be a mystery, it seems.
Hello
I live in France. I had the same issue this morning. The IP adress is 2a01:111:f402:f0a8::f138. It comes from Dublin
I changed my password.
I sent an email to MS support and I'm waiting its answer
Same here in Austria — 2FA enabled and suspicious logins from the following IPv6 addresses.
Paris
26.07.2025: 2a01:111:f402:f149::f143
27.07.2025: 2a01:111:f402:f149::f131
31.07.2025: 2a01:111:f402:f149::f132
Ireland
01.08.2025: 2a01:111:f402:f107::f135
I have the same problem. I'm based in Italy and it looks like someone succesfully accessed my account from Netherlands. However, the IP is slightly different:
2a01:111:f402:f047::f161
Jesus, this was bothering me. I even changed my password and forced a logout on all devices, but this log appeared again. Given the reports, it doesn't seem like a security issue, but rather something Microsoft has done.
Yeah sounds like Microsoft. First time I've ever been "hacked" and by Microsoft, worrying.
Same thing happened to me on Aug. 4 out of San Antonio (successfully log-in). I’m in Illinois. The ip address came back as being associated with Microsoft. My account is set to passwordless and 2FA, so there should be no successful log-in I would be unaware of. I forced logout on all devices and haven’t lost control of my email account or noticed any unusual activity in the account. This scared the shit out of me.
See this scared me too! And I’m actually based out of San Antonio geographically but keep getting logins from Phoenix. The whole thing is sketch and I’m sure there’s a good reason for it or at least an explainable one but big yikes.
Also had one from canada, apparently a Microsoft data center. would love to know if this in a hack or what. Microsoft please respond
Same issue happened to me in Canada as well. And the funny thing is, I changed my email alias 3 times so no one can use the old email for sign in, and guess what happened. That "IPv6" successfully signed in 3 times almost right away after I change the alias. No warning, no message, no authenticator approval, they just sign in like ghost. And Microsoft never responds to my post regarding the same issue.
Same for me although in my case the location is France - Paris to be exact.
No unusual 2fa codes asked for either so is very strange.
I have a similar situation. I checked my activity about a week ago and noticed a sign in the day before (august 3rd) from 2a01:111:f402:f0b1::f161, an address in Ireland. I thought this was a sign-in by someone else and that my password has been leaked at some point and I then secured my account further. I had 2FA and used it actively, but now went all passwordless and removed any legacy app-passwords, signed out from all my devices (which was only a few, and all known to me), moved my sensitve information in OneDrive into the "Personal vault". I created an alias and inactivated my e-mail address as means of sign-in method so now I have to sign in with an alias that no one can connect with my e-mail address. Now if anyone tries to sign in with my e-mail address as username the account doesn't exist. I have then checked my activity a few times per day. This morning I checked it from the MS Authenicator app and there was nothing. I then checked again tonight and there it was again a sign in from 2a01:111:f402:f0b1::f161 in Irland this morning. Pretty much the same time as I did sign in to check my account activity I believe. This lead me to search for the address and found this thread. I couldn't understand how anyone would be able to sign in after all measures I had taken. Yet it would be very good to hear some official response from MS about this and put some ease to this situation and the worries it creates for people. Gaining access to the e-mail alone is less then desirable, but if my OneDrive would be compromised it would be even worse I would say.
I am having the exact same issue. Yesterday, I signed out of every device and change my password, yet I still was able to notice a successful sign-in from San Antonio, even though my phone was not prompted for a 2FA.
Same thing here. It happened a few times now, all of them from Canada (I'm based in Brazil). I have commented in several posts about the same thing here and on reddit. Lots of reports about it.
I thought it was related to opening the outlook or onedrive app on my iPad, but last saturday I got the same successful login from Canada at 3:30am, a time I was obviously sleeping and not using anything. I've been worried about it for days. But now I just gave up.
Just wanted some official answer from Microsoft, cause this is really scary.
I’ve been dealing with the exact same issue. I contacted Microsoft multiple times already, they just keep giving me some generic suggestions, but no real help.
I got same issue. 2a01:111:f402:f0a5::f166 logged into my account from Dublin and I am from Spain.
Passwordless account.
https://unit42.paloaltonetworks.com/microsoft-sharepoint-cve-2025-49704-cve-2025-49706-cve-2025-53770/I came across this today - and it is a global problem. So basically Sharepoint server has been hacked which could make other platforms like onedrive vulnerable ; would definetly recommened to read as it could be the reason Microsoft are being so quiet about these data breaches, also the dates align with what people have been reporting. Take care!
key takeaway from article: "On-premises Microsoft SharePoint servers are currently facing widespread, active exploitation due to multiple vulnerabilities, collectively referred to as "ToolShell" (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771). These vulnerabilities enable attackers to achieve full remote code execution (RCE) without requiring any credentials. A compromised SharePoint server poses a significant risk to organizations, as it can serve as a gateway to other integrated Microsoft services."
Comfort Mmoledi,
Your assumption that those SharePoint vulnerabilities have anything to do with these completely unrelated IPv6 Activity log entries is inaccurate.
Though the article you referenced by PaloAlto Networks doesn't specifically mention it, it's been well known since at least July 22nd, per the following excerpt from the CISA article I'll reference below, that these vulnerabilities only affected on-premise SharePoint servers, not Microsoft's own cloud provided SparePojnt servers.
"CISA is aware of active exploitation of a spoofing and RCE vulnerability chain involving CVE-2025-49706 and CVE-2025-49704, enabling unauthorized access to on-premise SharePoint servers."
UPDATE: Microsoft Releases Guidance on Exploitation of SharePoint Vulnerabilities | CISA
Also note that SharePojnt and OneDrive are entirely separate systems operating on the Azure business and Microsoft Personal account-based systems respectively, so even if they might share portions of the same code that caused the vulnerabilities mentioned, that hasn't been confirmed in anything I've seen, nor should it matter, since the vulnerabilities themselves had been patched by Microsoft for their cloud-provided SharePoint servers before the exploitation of some customers unpatched on-premise SharePoint servers occurred. So even if OneDrive had contained similar code that might have been vulnerable, it's reasonable to expect that Microsoft would have realized this fact and fixed that parallel code as well, though I'd have expected them to mention this via a CISA or similar alert if it were actually true.
Microsoft has not been 'quiet about these data breaches' since everyone here with a level head has been stating there's nothing at all suspicious about these notifications, they're simply not something that most of those posting understand, so they're concerned because they don't have any past experience upon which to base the reason the notifications might be appearing in the Activity logs.
Those of us who understand that the mobile device apps that appear to be consistently involved in causing the log entries are often IPv6-based, quite often make connections with different servers in different countries, and in reality, may have little to do with the normal daily activities of the user himself, only find their sudden appearance for a limited subset of users globally an interesting curiosity.
In my case I've seen similar Activity display issues relating to IPv6 and specifically mobile devices as well back shortly after these first started to be supported officially on the Azure business platform a few years ago, since they also started to display with similar characteristics for Microsoft Personal account logins as well. However, since Microsoft clearly indicated more recently in the Activity logs that no maps were displayed for mobile devices, the appearance of these more likely back-end support connections within the Microsoft services operations displayed using IPv6 are obviously confusing to those without that same past experience.
I'm not saying I know for certain what every single one of these activity items might represent, but absolutely nothing I've seen described by anyone in the recent threads relating to these IPv6 entries has appeared truly suspicious, and in fact have always fit some of the less often described situations relating to either Microsoft Authenticator or other mobile applications like OneDrive that are known to operate in different ways than other apps.
Rob
Thank you for your time on this Rob; I just keep on getting those IPv6 entries appear in my activities and it has peaked my interest to do some digging into what may potentially be the cause.
Again, Thanks for clarifying.
Comfort
Comfort Mmoledi,
To be clear and simple about it, those users able to identify these log entries as related to access for either their Microsoft authenticator requests (think Push Notifications or others that obviously have to communicate directly with the servers to/from the app), or on rare occasions access via other apps like OneDrive, the explanation is simply that these apps are somehow accessing these servers in countries that often aren't typical for that user, which since these are specialized services that may not store data in those particular countries, is likely not strange at all.
The most confusing ones though might be those that occur at times the user himself doesn't seem to be involved at all and is sometimes even sleeping. But remember that maintenance tasks or even automated tasks the user has defined or selected themselves within the app might occur at these less busy moments, which since especially phones are typically 'always on' devices, isn't really so surprising if you think about it.
And since the Microsoft servers themselves often don't perform these tasks directly, since they require a client app to function, things like app clean-up of data on the servers might require a background authentication by either the device or some other process in order to function, leading to another often misunderstood impersonation log entry in the security logs of the device, which is one of the ways that Microsoft allows apps to take over and automate tasks the user himself might typically perform.
So in today's world of dynamic and automated systems we've all become accustomed to, none of this is truly suspicious or out of the ordinary, we just don't always notice or even get to see the actual operation of these actions, in many cases because the log entries themselves are actually suppressed both to reduce the number of excess entries stored, and also to avoid the kinds of confused and worried threads like this one, where non-technical individuals try to make sense of the highly technical and confusing processes required to make it all work.
I personally suspect that these recent IPv6 entries are actually just that, some set of entries that used to be suppressed that somehow a change in the systems involved has allowed a few of them to be logged and viewed.
Note that virtually all of those who've noticed are using the Microsoft Authenticator, and many seem to have been affected by the past issues where likely bots were attempting to attack that individual's Microsoft Personal account via password guessing in order to take over the account. In fact, that's really the reason many of these particular users are still checking the Activity logs, and what had them so rattled. While in truth, someone like me who spent 20 years as a Network Administrator in higher education and other businesses, as well as another 20+ as a security professional, had literally seen so many hundreds of thousands of these occurring daily against my users on the early Novell, Microsoft and Unix systems I managed even back in the 1990's, that I'm truly surprised my own long-ago exposed (to Spam) MSN - Microsoft Personal account has seen almost none of these for nearly a decade.
Rob
For me, this has been a hackathon and it continues. I have tried to lock down my account with multiple MFA‘s, signing out everywhere, password less, TOTP, standing on my head, etc. I still have successful signs from the exact same IPv6 address at the same geo location. Just had another one 12 hours ago
Earlier in August, I had 70 GB of data extracted out of my OneDrive via graph, which I have confirmed through looking at tenant logs. For those that are seeing these connections, make sure you check your https://entra.microsoft.com. I have the classic James Ridgeway in impersonated tenant ID. And since then, all of my information went into the dark web. I will never use OneDrive again.
@ Jim H
Do you use a personal or business Microsoft account? Have you checked the IP? Belongs it to MS?
Personal, formerly. I moved all of my data out of my OneDrive. Previously, I had an unauthorized device attached to my account called “PATROL-6004” near Springfield, Virginia. Has anyone else seen this? I don’t believe this is related to the recent BBC article regarding China’s “hacking“ of SharePoint. The IPV6 address(es) can be a misnomer. The feds and hackers use VPN’s. What concerns me is unauthorized devices connected to my account and seeing graph extractions!
Ok normally you can’t use Enatra ID with personal accouts or am I wrong. I don’t have any devices added to my account which are not mine.
You can see my newest experience in the comment of the BBC article :)
You are correct I think; Entra ID is for business accounts; you would need a tenant ID and you can pay for additional services etc. If you create a personal one drive you would have a seperate ID that just says Microsoft on the authenticator App on your phone. I cannot log into Entra ID because I have not used it in over 200 days so I am permenantly blocked.
I think for the graphs API which i've never heard of btw it only interacts with data people have given it and ofc granted permissions too, if you have a personal Onedrive i'm almost certain that Onedrive developers are not reckless enough for other developers to be able to access anyone's personal data from their personal Onedrives, if i'm wrong tell me I'm wrong but that would be ridiculous!
I have also recently seen this in the UK.
An early morning "successful sign-in" from an IPv6 address in the Netherlands (2a01:111:f402:f0c4:f142). I have 2FA enabled, wasn't in the Netherlands and didn't knowingly get a notification from the Microsoft Authenticator app (unless it timed out when I was asleep).
Following - same scenario with me. Based in US, successful sign in in Phoenix.
Same for me. I've enabled 2FA and the other (expected) Recent Activity showed "Additional verification requested" below successful sign-in activity but this one did not show "Additional verification requested". I think this could be a Microsoft Data center IP address but not sure. None of my other logins used IPv6 addresses. Changed my password just to be safe.
I'm based in Australia, and had the same location show up as a recent sign in.
Same here, I'm from México
Same to me. Yesterday and on July 29th. Both different IPv6 registered to Microsoft.
I beleve its a bug. What else should it be. My account war vry secrue because of 2FA e.g. and like you other told you had your 2FA enabled and nothing happed to the account like by me from my opinion it only could be an MS problem.
Glad I'm not alone with this issue. I'm in Oz and someone from this address :-2a01:111:f402:f064::f153 was showing up. According to Co Pilot its Microsoft.
The IPv6 address is part of a subnet assigned to Microsoft Azure, and it's associated with the autonomous system AS8075 (MICROSOFT-CORP-MSN-AS-BLOCK).
🌏 Location Details:
• Country: United States
• Region: Virginia
• City: Washington
• Latitude/Longitude: 38.7095, -78.1539
• Organization: Microsoft Corporation
This IP is classified as a public IPv6 address, and it's not listed on any known blacklists or TOR exit nodes.
It bypassed all my security, eg Passwordless login, 2FA and Passkey. Didn't get any prompts from Authenticator. I did reset and report and signed out of everywhere. Very time consuming.
Asked Co Pilot why they looked into my activity page, his/her response.........
Great question—and it’s one that’s puzzled a lot of users.
🧠 Why Microsoft IPs Show Up in Your Outlook Activity Page Microsoft isn’t “going into” your account in a suspicious way. When you see IPs like 2a01:111:f402:f064::f153
in your Recent Activity, it usually means:
🔐 What the Activity Page Actually Tracks According to Microsoft Support:
If you see something unfamiliar, you can mark it as “This wasn’t me” and Microsoft will guide you through securing your account.
🛡️ Bottom Line: Microsoft isn’t snooping—it’s just logging legitimate service activity. But if you’re ever unsure, it’s smart to:
Want help walking through your security settings or checking if any activity looks off?
Great question—and it’s one that’s puzzled a lot of users.
🧠 Why Microsoft IPs Show Up in Your Outlook Activity Page
Microsoft isn’t “going into” your account in a suspicious way. When you see IPs like 2a01:111:f402:f064::f153
in your Recent Activity, it usually means:
🔐 What the Activity Page Actually Tracks
According to Microsoft Support:
If you see something unfamiliar, you can mark it as “This wasn’t me” and Microsoft will guide you through securing your account.
🛡️ Bottom Line:
Microsoft isn’t snooping—it’s just logging legitimate service activity. But if you’re ever unsure, it’s smart to:
Want help walking through your security settings or checking if any activity looks off? Mind you Co Pilot could be "towing the party line"!!!!!!
Literally the same as you, im glad we’re on all the same page, I got the first log in on 30th July then 2nd August, ip address 2a01:111:f402:f07c::f172. When I searched it said it’s a Microsoft data center. This sounds like an invasion of privacy. It also bypassed my security stuff. Im guessing this must be a bug or some Microsoft infrastructure or something because I used to get the same ip address on my work email and nothing more.
What’s more worrying that I forgot to mention is that Passwordless login had been turned off and I never turned it off!!!!!! Conspiracy theories abound in my head. Haha I've always been paranoid about locking down accounts but now I'm super paranoid. I used to get scores of attempts to access my emails every day and then it suddenly stopped, and I became lax at checking. Then bored the other day I thought I would look around and check email activity pages. Shock, horror and panic set in for a while.
I am getting sign-ins from San Antonio as well. Like others, I have taken all security precautions and have Defender, etc. It was odd, I used to see unsuccessfulI sign-ins from all over the world. Then they just stopped. I was pleasantly surprised. Now I get this address signing in every few days. I can’t keep checking like this. Not to mention, I don’t always see it until hours later. I do not receive any notifications or alerts, despite having to enter a code myself every time. The only concern is the ip address is listed somewhere London and not San Antonio. 2a01:111:f402:f034::f153 This is getting rather old and if it is Microsoft, they should list it next to the sign-in or be transparent if they can’t stop these actions.
Right click on IP address and you come up with is..............................The provided IPv6 address, 2a01:111:f402:f034::f153, is associated with a Microsoft Limited IP address. It's worth noting that some IPv6 addresses can be dynamically generated by the SLAAC privacy extension, meaning they may change over time. The IP address in question has been reported four times on AbuseIPDB, but the confidence of abuse is currently marked as 0%
Thank you for your reply. I appreciate it. I did see that information. My question is for you or anyone…we are told to secure our account if the sign-in looks unfamiliar. If it is indeed a Microsoft IP address or server (not sure what to call it) why can’t it be identified as such? I don’t want to ignore these sign-ins and become complacent in thinking it’s just Microsoft. I do feel we shouldn’t be left in the dark. There’s a huge difference between we bounced you off a different server or address, than someone was able to sign in to your account, and has had access for quite a while. I have done every suggestion known. I just want to know if my information is safe or was my account accessed from an outside source, repeatedly.
So then you will have to call Microsoft support. I don’t see any other options because no Microsoft employee answers to this in here.
My logins with such IPs are at the same time I used the personal vault in OneDrive so I am very sure it’s a display bug.