A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Unexpected Authenticator prompts can mean one of three things:
- Someone is trying to access the account.
- Someone entered the wrong phone number or email by mistake.
- A previously requested prompt was delayed.
A stronger sign of an actual attack is a pattern such as:
- many repeated sign-in attempts
- failed authentications
- sign-ins from multiple IP addresses
- unusual or unfamiliar locations, browsers, operating systems, or apps
- repeated interrupted sign-ins, especially where the password is correct but strong authentication is required
To check whether this is suspicious:
- Do not approve any prompt that was not initiated. Select Deny for requests that were not requested.
- Review recent sign-in activity:
- For a work or school account, go to My Account > Recent Activity and review each sign-in.
- Look beyond location alone. Mobile networks and VPNs can make locations appear wrong. Also check the operating system, browser, and app.
- If any successful sign-in is not recognized, change the password immediately and then review/update Security info.
- If prompts continue, consider moving to a passwordless sign-in method if available for the account, since Microsoft documents this as a way to further secure the account.
What would indicate a likely attack in this case:
- six prompts in 18 hours is not normal if none were initiated
- if the recent activity page shows repeated failed attempts, multiple IPs, or unfamiliar successful sign-ins, that is a strong indicator of someone trying to get in
- if there are only failed or denied attempts and no recognized successful sign-in, the account is still protected as long as no unexpected prompt or code is approved
For work or school accounts, if a phone was lost or stolen or sign-in methods need to be reset, the organization Help desk can clear the settings.
References: