A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Repeated unrequested Authenticator prompts usually mean someone is repeatedly trying to sign in with the account.
To protect the account and reduce the impact:
- Deny every request
- Always select Deny on any sign-in prompt or notification that was not initiated.
- Do not share any verification codes with anyone.
- Change the password and review security
- Immediately change the account password to a strong, unique one.
- Review recent sign-in activity and security info for anything unfamiliar (devices, phone numbers, email addresses) and remove anything not recognized.
- Strengthen sign-in methods
- Ensure two-step verification / MFA is enabled and correctly configured.
- Prefer passwordless methods such as Microsoft Authenticator, Windows Hello, SMS/Email codes, or security keys as described in the passwordless guidance.
- Understand the risk of multiple attempts
- Multiple failed attempts can temporarily block sign-ins as a protection mechanism; this is designed to help protect the account, not permanently lock it out.
- If sign-in is blocked after many attempts, wait and try again later or use an alternate MFA method if available.
- If suspicious activity continues
- Treat this as a possible attack on the account.
- For work or school accounts, contact the organization’s IT administrator or Help desk and ask them to review Microsoft Entra sign-in logs and, if needed, reset MFA settings.
As long as unrequested prompts are denied and verification codes are not shared, those attempts cannot successfully access or permanently block the account.
References: