MS Log-in attempts not showing as "Failed"?

ABM 40 Reputation points
2026-06-08T13:19:19.7366667+00:00

Today I received two push notifications via mobile from unknown devices trying to access my MS account which I understand happens to a lot of users and usually I'd waive it off however there's no "Failed attempts" within my activity tracker. As a user who is already using 2FA I'm confident enough that my account won't be accessed but I'm concerned that logs of said attempts are not tracked.

That being said is there a setting I don't have "ticked" on Authenticator that I may be missing? Is this a common problem? Do the denied attempts not flag as "Failed"?

I hope I'm asking the right questions in the right place and thank you for your time in advance.

Microsoft 365 and Office | Subscription, account, billing | For business | Other
0 comments No comments

Answer accepted by question author

Alina Le 3,505 Reputation points Independent Advisor
2026-06-08T14:37:11.6933333+00:00

Hello @ABM

As I have reviewed, denied sign‑in attempts in Microsoft Authenticator usually don’t appear as “Failed” in your account activity. The system only logs completed sign‑ins (successful or failed due to wrong password/timeout). When you tap Deny, the login is stopped before completion, so it isn’t flagged the same way. This is expected behavior, not a missing setting in Authenticator.

As I have shared it for other users, I want to share it again just in case you want to use it to protect your account in the future.

What is the recent activity page?

In this case, I recommend taking the following steps to further strengthen your account security and prevent repeated notifications based on your account type:

1/ If you are using personal account:

You can try to "Add an extra layer": Alias sign-in trick (Recommended)

You can set up an additional sign-in alias. These options help reduce unwanted sign-in attempts and provide an extra layer of protection.

This is a pro move to stop attacks almost entirely:

  • Create a new email alias (e.g., random string)
  • Set it as your primary login email
  • Disable login for your old email
  • Result: Attackers can’t even try logging in anymore

For your reference: Change the email address for your Microsoft account | Microsoft Support

2/ If you are using business account:

You can reach out to your IT Admin, who has global administrative rights in your organization’s tenant, to help strengthen your account security and prevent repeated notifications by referencing this thread.

Getting too many authentication attempts on my account - Microsoft Q&A

If you still need my assistance, please come back with screenshots or any additional details so I can review it again and see if there’s anything more I can help you with.  

Wishing you all the best!


If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".  

Note: Please follow the steps in "our documentation" to enable e-mail notifications if you want to receive the related email notification for this thread.

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

Answer accepted by question author

AI answer

2026-06-08T13:19:57.8833333+00:00

Denied or unrequested sign-in prompts can occur without always appearing as obvious “failed sign-ins” in the user-facing activity views.

Key points based on how Microsoft handles these events:

  1. Unrequested prompts are expected in some scenarios The Outlook/Microsoft sign-in prompt “Are you trying to sign in?” can appear when:
    • Someone is trying to access the account.
    • Someone mistyped the phone/email when trying to sign in.
    • A previously requested prompt was delayed. In all these cases, the guidance is to select Deny for any request not initiated by the user. Without the correct response and approval, the account remains protected.
  2. Not all events are surfaced as “failed attempts” to end users
    • Microsoft’s security systems detect unusual activity (for example, repeated sign-in attempts or sign-ins from new locations/devices) and may block or challenge them.
    • Some of these events are primarily visible to administrators via Microsoft Entra sign-in logs and risk detection tools, not necessarily in the consumer-facing “Recent activity” or simple “failed sign-in” counters.
    • The Recent activity page explicitly shows only “significant events that could impact your account security,” and not every single attempt. Multiple similar events from the same device/location may be collapsed or not shown individually.
  3. What to do when seeing unrequested prompts
    • Always tap Deny on any prompt not initiated by the user.
    • Check the Recent activity page for unusual sign-ins or profile changes and, if anything looks suspicious, select Secure your account.
    • Keep security contact information (phone/email) up to date on the Security basics page so alerts and verification codes can be delivered reliably.
  4. No additional Authenticator “setting” is required
    • There is no extra toggle in Microsoft Authenticator that must be enabled for these denied prompts to be logged.
    • The absence of clearly labeled “failed attempts” in the user-facing view does not mean the attempts are not tracked internally; it reflects how Microsoft chooses which events to surface to end users.

In summary, denied prompts may not always appear as explicit “failed sign-ins” in the activity tracker, but they are handled by Microsoft’s security systems. The correct action is to deny any unrequested prompt and review Recent activity for significant events.


References:

AI-generated content may be incorrect. Read our transparency notes for more information.

Was this answer helpful?

1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.