someone is trying to login into my account

oxy sefu 15 Reputation points
2026-06-04T10:24:36.25+00:00

hello, i get notifications everyday that people from US or Canada are trying to connect into my account but i deny every time, even so, i changes my password and activated the 2FA, still get notifications om people trying to log in. what can i do?

Microsoft 365 and Office | Subscription, account, billing | For business | Other
0 comments No comments

3 answers

Sort by: Most helpful
  1. Julie Huynh 1,615 Reputation points Independent Advisor
    2026-06-04T15:28:12.1566667+00:00

    Dear @oxy sefu,

    Good day! Welcome to Microsoft Q&A forum!

    Based on your description, I understand that you’re receiving repeated notifications about login attempts from locations like the US or Canada trying to access your account. Although you’ve denied all attempts, updated your password, and enabled two-factor authentication, the login notifications are still occurring and you’re looking for guidance on how to stop them and secure your account.

    To make sure I understand your situation accurately, could you please confirm:

    • Are you currently able to access your account without any issues?
    • Are you using a personal Microsoft account (e.g., @outlook.com / @hotmail.com) or a work/school account (e.g., @yourcompany.com)?
    • Are the alerts coming through the Microsoft Authenticator app, email, or both?

    Your confirmation would be very helpful in ensuring you receive the most suitable support!

    Based on what you described, receiving repeated unauthorized sign-in attempts from different countries can definitely feel alarming.

    In most cases, this happens when your email address becomes exposed online (for example, through data leaks or public listings). Automated tools on the internet then try to sign in using that email.

    The good news is that your two-factor authentication (2FA) is doing its job and by denying these requests, you’re actively preventing access.

    Furthermore, depending on your account type:

    1-If you are using a Personal account: You may want to try the alias sign-in method (highly recommended):

    2-If you are using a Business account: I recommend contacting your IT administrator within your organization.

    They can:

    Kindly let me know when there are updates or if you need further assistance. Any updates you’re able to share would be really helpful. I appreciate your time and look forward to hearing how things are going! 

    Thank you for your time and patience.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".  

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.  

    Was this answer helpful?

    1 person found this answer helpful.

  2. Hassan 0 Reputation points
    2026-06-05T23:20:26.2433333+00:00

    Same here getting same creepy alerts and 2FA pop-ups.
    Is Microsoft under attack?

    Was this answer helpful?


  3. AI answer

    2026-06-04T10:24:51.23+00:00

    Unrequested sign-in prompts and verification codes usually mean either someone is trying to access the account, someone mistyped their email/phone, or a delayed prompt/code is arriving later. Denying every request and having 2FA enabled already protects the account, because attackers cannot sign in without the correct second factor.

    To further secure the account and reduce risk:

    1. Review recent sign-in activity
      • For a personal Microsoft account, go to the Recent activity page from the Security basics area and review all sign-ins for the last 30 days. If any activity is not recognized, mark it as not you and follow the prompts to secure the account.
      • For a work or school account, sign in to My Account, select Recent Activity, and review each sign-in. If anything looks unfamiliar, immediately change the password and then go to Security info to update security methods.
    2. Confirm security info and 2FA methods
      • On the Security basics or Security info pages, verify all phone numbers, email addresses, and authenticator registrations.
      • Remove any phone, email, or app registrations that are not recognized.
      • Ensure at least one trusted method (such as Microsoft Authenticator, SMS, or email) is current and under control.
    3. Do not approve unrequested prompts or codes
      • For Microsoft Authenticator or Outlook mobile prompts that say “Are you trying to sign in?”, always select Deny if the sign-in was not initiated.
      • For verification codes received without requesting them, ignore them and do not enter them anywhere.
    4. Strengthen sign-in security
      • Keep a strong, unique password and do not reuse it on other sites.
      • Consider going passwordless (for work/school accounts) using methods like Windows Hello, Microsoft Authenticator, SMS/email codes, or security keys to reduce password-based attacks.
    5. If sign-in attempts are excessive or suspicious
      • For work or school accounts, contact the organization’s IT administrator and ask them to review Microsoft Entra sign-in logs for repeated or malicious attempts.
      • If unable to sign in due to too many attempts, wait for the lockout period to expire or use a different MFA method if available.

    As long as all unrequested prompts are denied, verification codes are ignored, and security info is correct, attackers cannot complete sign-in and the account remains protected.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.