Share via

Someone keeps trying to get into my account

marcello pica 0 Reputation points
2026-04-18T15:37:02.16+00:00

I keep getting notifications on my Authenticator that someone is trying to login. I keep pressing deny but what can I do to make it stop before they eventually get into my account?

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Most helpful
  1. Q&A Assist
    2026-04-18T15:37:14.54+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    Select Deny on every sign-in request not initiated personally and then harden the account so the attacker cannot succeed.

    1. Treat the prompts as a possible attack
      • Unrequested prompts can mean:
        1. Someone is trying to access the account.
        2. Someone mistyped the phone/email when signing in.
        3. A delayed delivery of an old prompt.
      • For any request not initiated, always select Deny. Without approval, the attacker cannot complete sign-in.
    2. Review recent sign-in activity
      • Go to the Security basics page and select Review activity.
      • On the Recent activity page, look for unfamiliar sign-ins:
        • If activity is in Unusual activity, expand it and select This wasn’t me.
        • If it’s in Recent activity, expand it and select Secure your account.
      • This flags suspicious attempts and walks through securing the account.
    3. Change the password immediately
      • From the Security basics page, select Change password.
      • Set a strong, unique password not used on any other site.
      • Do not share the password with anyone.
    4. Strengthen sign-in and verification methods
      • Ensure Microsoft Authenticator is the primary method and that only personal devices are registered.
      • Remove any phone numbers, emails, or devices in the security info that are not recognized.
      • Consider going passwordless (for work/school accounts) using methods such as Microsoft Authenticator, Windows Hello, SMS/Email codes, or security keys to reduce reliance on passwords that can be guessed or phished. See How to go passwordless with your Microsoft account.
    5. If repeated attempts block sign-in
      • Microsoft Entra multifactor authentication can temporarily block sign-in after repeated attempts.
      • If mistakenly making many attempts, wait and try again later or use a different MFA method.
      • If it looks like someone else is trying to access the account, contact the organization’s IT administrator so they can review Microsoft Entra sign-in logs and adjust MFA settings if needed.
    6. If unusual sign-in alerts continue
      • Keep denying all unrequested prompts.
      • Regularly monitor the Recent activity page and mark anything not recognized as This wasn’t me or Secure your account.
      • Ensure all security contact info (phone, alternate email) is current so alerts and verification codes always reach the correct devices.

    As long as unrequested prompts are denied and the account password and security info are secured, the attacker cannot complete sign-in, and Microsoft’s unusual-activity protections will continue to help block unauthorized access.


    References:

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.