Managing personal Outlook.com account settings, security, and privacy
Same issue. Its annoying and stupid. I want to be able to force those bots to insert a correct password before they can prompt for 2FA. Currently its not possible.
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Hello,
I am receiving numerous unauthorized login attempts per day on my Microsoft / Outlook account. Each attempt triggers a 2-factor authentication notification requesting a code, which I did not initiate.
To be clear, my account is already configured with maximum available security, including:
Multi-factor authentication enabled
Microsoft Authenticator app
Up-to-date recovery information
Regular review of sign-in activity
No login attempts have been successful, and I do not approve any of these requests. However, the volume of attempts is persistent and disruptive.
My question: How can I block or prevent the source of these repeated login attempts? Is there any way to:
Block specific IP addresses, regions, or devices?
Rate-limit or suppress repeated authentication prompts?
Escalate this as a targeted or automated attack against my account?
I understand that Microsoft does not disclose attacker details, but I would like to know if additional protections or controls are available beyond the standard security features already in place.
Thank you for any guidance on how to fully stop or mitigate these ongoing attempts.Hello,
I am receiving numerous unauthorized login attempts per day on my Microsoft / Outlook account. Each attempt triggers a 2-factor authentication notification requesting a code, which I did not initiate.
To be clear, my account is already configured with maximum available security, including:
Passwordless sign-in
Multi-factor authentication enabled
Microsoft Authenticator app
Up-to-date recovery information
Regular review of sign-in activity
No login attempts have been successful, and I do not approve any of these requests. However, the volume of attempts is persistent and disruptive.
My question:
How can I block or prevent the source of these repeated login attempts?
Is there any way to:
Block specific IP addresses, regions, or devices?
Rate-limit or suppress repeated authentication prompts?
Escalate this as a targeted or automated attack against my account?
I understand that Microsoft does not disclose attacker details, but I would like to know if additional protections or controls are available beyond the standard security features already in place.
Thank you for any guidance on how to fully stop or mitigate these ongoing attempts.
Managing personal Outlook.com account settings, security, and privacy
Same issue. Its annoying and stupid. I want to be able to force those bots to insert a correct password before they can prompt for 2FA. Currently its not possible.
I have exhausted all options. I'm preparing to go extreme and delete all Microsoft accounts from all my devices.
@David Pace Sr said
if the "passwordless" accounts are better or worse to fix the problem.
@k w said
“just change your login username” is not a real solution. Most people have had the same email for years. Security shouldn’t depend on hiding your username.
The solution being proposed has nothing to do with passwords, or the lack thereof, and does not impact the ability of your old email address to send and receive mail.
Login Only Alias
You create a new "secret" alias that only you know. You use it ONLY to logon to your account. Then you remove the Sign-In privilege from your existing email alias so it can not be used to logon to your account but can still be used to send and receive email. Now, if all the Bad Guys have is your old alias, they get "This username has been turned-off for sign in" at the very first step of the logon process and can not continue.
1 -- Create a new Log In Only (LIO) alias. (e.g. "JohnDoe.LIO@...")
https://account.live.com/AddAssocId
2 -- Make the LIO alias your Primary Alias.
https://account.live.com/names%2FManage
3 -- Log out of your account.
Click on your Initials/Profile Picture at the top right and choose "Sign out"
4 -- Verify that you can login using the new LIO alias.
5 -- Uncheck the Sign-in privilege from your old alias. It's now an Email Only (EMO) alias.
https://account.live.com/SignInPreferences
6 -- Change your default "Send From" in Outlook to your old EMO alias.
https://outlook.live.com/mail/0/options/mail/forwarding
-> Email aliases -> Set default From address
References:
https://www.outlook-tips.net/tips/keeping-hackers-microsoft-accounts/
I'm having the same problem with at least 10 to 12 login attempts to my account per day.
However, before the attempts/attacks started I received a message that my Microsoft Login information was found on the Dark web.
My questions are to find out if the "passwordless" accounts are better or worse to fix the problem.
Did everyone else here get a warning also, about having your login information compromised, before getting the login attempts?
And if not, and you're sure that your login info was not compromised, were you using a password with login or using the "passwordless" feature?
Because, after reading that the solution was "changing your alias" it makes me wonder if that's all anyone needs for bruteforce attempts to trigger the confirmation requests.