Microsoft authenticator weird login attemps

Fredrik Mattsson 0 Reputation points
2026-10-01T07:19:35.6533333+00:00

Almost every time I open Microsoft authenticator it asks me to verify a login from some random corner of the earth that I have to deny. Can i prevent this? Does it mean my password is compromised?

Microsoft Security | Microsoft Authenticator
0 comments No comments

2 answers

Sort by: Newest
  1. Nam-D 4,080 Reputation points Microsoft External Staff Moderator
    2026-10-01T14:06:56.9933333+00:00

    Hello @Fredrik Mattsson,

    As the AI answer noted, repeated unexpected Microsoft Authenticator prompts usually mean someone is attempting to sign in and has reached the verification step. This does not mean the account is compromised, but the prompts should never be approved.

    This can happen when someone knows your Microsoft account username and is attempting to sign in. Therefore, please follow these steps to help secure your account:

    1 - If you are using a Personal Microsoft Account

    You can use any of your aliases to sign in, and you can select any of them for sending and receiving email. Verification codes sent by email can only be sent to your primary alias or another email address added as a verification method. Therefore, you can change your primary email address while you still able to use it as alias email. Prevent from unknown sign-in attempts.

    You may follow the steps in the Microsoft KB below to add a new alias: Change the email address for your Microsoft account | Microsoft Support

    To help stop unauthorized sign-in attempts, you can:

    • Create a new email alias (a random string)
    • Set the new alias as your primary sign-in email
    • Disable sign-in access for the old email alias

    As a result: Unknown users will no longer be able to attempt sign-ins using your previous exposed email address.

    2 - If you are using Business Account

    If you are an end-user, you can reach out to your Global Administrator or IT Support team to further improve account security and help prevent repeated authentication notifications. They can support to change your primary email address and keep the current email as alias so you can keep send and receive email from the alias email address. For more information on how to change alias: Add another email alias for a user - Microsoft 365 admin | Microsoft Learn

    To review your account activity, you can go to https://mysignins.microsoft.com/ . Then select Recent activity from the left pane

    User's image

    If you are an administrator, you can check the sign-in logs in https://entra.microsoft.com/

    1. Navigate to Users > All users. User's image
    2. Search for your account and open the Sign-in logs. User's image
    3. The sign-in logs will display all login attempts, including whether they were successful or failed. You can review the status messages in the event details for more information. For example:   Screenshot of the sign-in error code on the basics tab.

    Supported KB:  

    If you have any further concern, please feel free to let me know.


    If you found the answer helpful, kindly click the "Yes" button below. If you have any further questions about this answer, please click "Comment."

    Was this answer helpful?

    0 comments No comments

  2. AI answer

    2026-10-01T07:19:58.7066667+00:00

    Repeated unexpected Microsoft Authenticator prompts usually mean someone is trying to sign in with the account and is reaching the verification step. It does not by itself mean the account has already been compromised, but it does mean the sign-in name is being targeted and the prompts must never be approved.

    What to do:

    1. Keep denying unexpected prompts If a sign-in is not expected, select Deny. Fraudulent transactions and unauthorized access are blocked when the request is denied.
    2. Do not share verification codes Verification codes change every 30 seconds. They should never be read to anyone over a call or text. Microsoft specifically warns that attackers may pretend to be support or another trusted organization and ask for the code.
    3. Review recent sign-in activity
      • For a work or school account: sign in to My Account and open Recent Activity from the left pane.
      • In Microsoft Authenticator for a work or school account: open the account home page and select Recent account activity. If unfamiliar activity appears, change the password and update security settings.
    4. Change the password if there are suspicious sign-ins If sign-in history shows activity that was not authorized, change the password immediately. For work or school accounts, Microsoft recommends updating security settings from the Security info page as well.
    5. If this is a personal Microsoft account and the prompts keep coming, change the primary alias used for sign-in Accepted Microsoft Q&A guidance says persistent prompts can continue even after a password change because attackers may keep trying an exposed sign-in address. Changing the primary alias and disabling sign-in on the old alias can stop those repeated attempts while keeping the mailbox.
    6. If this is a work or school account, contact the IT admin if the issue continues If the prompts persist after reviewing activity and securing the account, the documented next step is to reach out to the IT admin or helpdesk.

    About the random locations:

    • Location can look strange or distant in sign-in records because IP-based location is approximate, especially on mobile networks.
    • Also, Microsoft Entra documentation notes that anomalous sign-ins may not generate push notifications automatically; approval may require opening Authenticator and refreshing.

    Bottom line:

    • Unexpected prompts do not prove the password is compromised.
    • They do mean the account is being targeted and the prompts should always be denied unless the sign-in was initiated intentionally.
    • If suspicious activity is visible, change the password and review/update security info.
    • For personal accounts with constant prompt spam, changing the primary sign-in alias is the strongest documented mitigation in the provided guidance.

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.