The message shown is the standard “unusual sign-in activity” notification Microsoft sends when a sign-in from a new location, device, or app is detected. Legitimate security alerts for Microsoft accounts are sent from the Microsoft account team at an address ending in @accountprotection.microsoft.com, which matches what is shown.
However, the email alone should never be trusted as proof of compromise. The correct next step is to verify activity directly in the account, not via the email content:
- Open a browser and manually go to the Recent activity page by entering
https://account.live.com/Activity or by signing in to the Microsoft account dashboard and navigating to Security → Recent activity.
- Review the last 30 days of sign-ins. Check:
- Date and time
- Country/region and IP address
- Device, platform, browser, and app
- If the sign-in in the email appears there and is not recognized, mark it as This wasn’t me on the Recent activity page. Follow the prompts to secure the account.
- If there is any suspicion that someone else may have accessed the account, immediately:
- Change the account password.
- Update security info (phone number, alternate email) on the Security settings / Security basics pages.
- Remove any devices marked as trusted.
If the email address in the body of the message is not the actual Microsoft account in use, still sign in to the correct Microsoft account and check Recent activity as above. Do not click any links in the email if there is any doubt; always navigate manually.
If more help is needed securing or recovering the account, use the guidance under “Get more help protecting your Microsoft account.”
References: