Someone keeps trying to access my Microsoft account – Authenticator notifications won’t stop even after password change

Solomon Matteo 0 Reputation points
2026-05-28T13:31:18.35+00:00

Hi everyone,

I’ve been dealing with a concerning issue for the past few days and I’m hoping someone here can help.

Every single day I receive multiple Microsoft Authenticator approval requests that I did NOT initiate. Someone is clearly attempting to log into my account repeatedly. I have already changed my password, but the unauthorized sign-in attempts are still happening and the Authenticator notifications keep coming.

What I’ve done so far:

•	Changed my Microsoft account password

•	Denied all suspicious Authenticator requests

What I need help with:

•	How do I stop these login attempts completely?

•	Should I remove and re-add my account in Authenticator?

•	Is there a way to see where these attempts are coming from (IP/location)?

•	Do I need to revoke all active sessions?

I’m worried my account may have been compromised in some way beyond just the password. Any advice would be greatly appreciated.

Thanks in advance.

Microsoft Security | Microsoft Authenticator
0 comments No comments

2 answers

Sort by: Most helpful
  1. GL 16 Reputation points
    2026-06-15T14:07:55.77+00:00

    I stopped reading the A.I. answer when it said to change the password because MS has actually put in an express lane for the bad guys. I made this fun little picture that describes the 3 simple steps that anyone on the planet can use if they know your account...MS poor security choice

    The upside is, you have your phone, so they still can't get in, but whenever they want to, they can make your phone give you a notification (see also: "MFA Fatigue")

    Thank you, Microsoft! --eyeroll--

    Was this answer helpful?

    10+ people found this answer helpful.

  2. AI answer

    2026-05-28T13:31:41.1366667+00:00

    The repeated Microsoft Authenticator prompts mean someone still has the correct username and is repeatedly trying to sign in, but multifactor authentication (MFA) is blocking them. Changing the password was the right first step; now the focus should be on securing the account and reviewing activity.

    Actionable steps:

    1. Review recent sign-in activity and confirm it isn’t legitimate
      • Go to the Security basics page and open Review activity / Recent activity.
      • On the Recent activity page, expand each suspicious sign-in.
      • For any attempt that is not recognized, select This wasn’t me (for Unusual activity) or Secure your account (for Recent activity). This both flags the activity and walks through securing the account.
      • The activity list shows time, app/device, and location (approximate, based on IP), which answers the “where is this coming from” question.
    2. Change password again and secure the account
      • From the Security basics page, select Change password and set a strong, unique password not used on any other site.
      • If there is any suspicion that someone else accessed the account, follow the guidance under If someone has accessed your account and Notify us if you don't recognize activity on your account to secure it.
    3. Check and update security info / MFA methods
      • On the Security pages, review all phone numbers, email addresses, and sign-in methods.
      • Remove any security info or sign-in alias that is not recognized.
      • Ensure Microsoft Authenticator and other MFA methods (SMS/email/security key) are ones that are controlled.
      • Going “passwordless” (for example, using Microsoft Authenticator, Windows Hello, or a security key) can reduce reliance on passwords and make attacks like password guessing less effective. See How to go passwordless with your Microsoft account from the verification-code troubleshooting article.
    4. Handle the repeated Authenticator prompts
      • Continue to deny all prompts that were not initiated.
      • Authenticator may deny authentications when GPS/location is inconsistent, and it can show approximate locations; use that as an extra check, but rely primarily on whether a sign-in was initiated.
      • If notifications are overwhelming, do not turn off MFA; instead, focus on stopping the attacker’s ability to sign in by changing the password and securing the account as above.
    5. Revoke active sessions and app access (where available)
      • From the Microsoft account security pages, use options such as sign out everywhere or similar (where available) to invalidate existing sessions on other devices.
      • Then sign back in only on trusted devices.
    6. If sign-in attempts are excessive or unusual
      • Microsoft may temporarily block some verification methods or sign-ins when there is unusual activity or a high volume of requests, which can help protect the account. This can result in messages like “Try another verification method.” In such cases:
        • Try another verification method already configured (for example, alternate email instead of SMS).
        • Avoid repeated attempts; if blocked, wait at least 24 hours before trying again, as repeated attempts can extend the block.
    7. Device and network hygiene
      • Run security scans on devices used to sign in, to ensure there is no malware capturing credentials.
      • If sign-in attempts continue even after a password change and cleanup, consider changing passwords on other accounts that might share the same password and ensure no password reuse.

    Regarding specific questions:

    • “How do I stop these login attempts completely?”
      They cannot be fully prevented if someone keeps guessing the username, but changing to a strong unique password, reviewing recent activity, removing unknown security info, and revoking sessions will prevent successful access. Over time, failed attempts usually decrease once they stop being effective.
    • “Should I remove and re-add my account in Authenticator?”
      This is optional and mainly useful if there is concern that the Authenticator configuration itself is corrupted. The core issue is that someone knows the username and is trying to sign in; removing/re-adding Authenticator does not stop attempts, but ensuring only personal devices are registered is important.
    • “Is there a way to see where these attempts are coming from (IP/location)?”
      Yes. Use the Recent activity page from the security guidance. It shows sign-in time, app, platform, and approximate location based on IP.
    • “Do I need to revoke all active sessions?”
      Yes, this is recommended after suspected compromise: sign out of all sessions and then sign back in only on trusted devices.

    If sign-in issues or verification-code problems appear (for example, “Try another verification method” or “Error 400”), use the guidance in the verification-code troubleshooting article to switch methods, change networks, or wait out temporary blocks.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.