I am writing about two related issues on my Microsoft account.
- Ongoing unauthorized sign-in attempts
Almost every day I receive notifications via the Microsoft Authenticator app asking me to approve a sign-in that I did not initiate. I have changed my password multiple times, but this has not stopped the attempts. I have also received one-time verification codes that I did not request. I am concerned the account is being actively targeted.
- Unable to register a FIDO2 security key
I am trying to add a FIDO2 security key (YubiKey 5 NFC) as a sign-in method, but registration consistently fails with a "Something went wrong" error.
Troubleshooting already completed for issue 2:
- Confirmed the key is detected correctly by the system (ykman fido info shows the key is functional, PIN configured, FIDO2 enabled)
- Successfully registered and authenticated the same key on an independent FIDO2 test site (webauthn.io)
- Successfully added the key as a Windows Hello sign-in method on my PC
- Tried registration in two different browsers (Microsoft Edge and Brave), both fail identically
- Reset and reconfigured the key's PIN, retried registration
- Restarted the computer and retried
Given that the key works correctly outside of Microsoft's website, I suspect there may be a restriction on the account preventing new security key registrations – possibly related to the repeated suspicious sign-in activity described above.
Could you please:
- Investigate the source of these repeated unauthorized sign-in attempts, even after password changes
- Investigate why security key registration is failing on this account
- Advise on next steps to fully secure the account
Thank you for your help.