Non used sign-in attempt notification

Ryan May 0 Reputation points
2026-07-06T23:13:00.3966667+00:00

If I get a sign in attempt notification via the authenticator app but it’s not me trying to log in, is it possible to see where the request came from and how concerned should I be?

Microsoft 365 and Office | Subscription, account, billing | For business | Other
0 comments No comments

2 answers

Sort by: Most helpful
  1. Alina Le 3,500 Reputation points Independent Advisor
    2026-07-07T04:31:02.16+00:00

    Hello @Ryan May

    Receiving unauthorized access attempts to your account is understandably concerning.

    I understand that you would like to trace the source of these attempts, but the available information depends on the type of account you are using.

    • For a personal Microsoft account:

    From my understanding, the system typically logs completed sign-in activities, such as successful sign-ins or failed sign-ins caused by incorrect passwords, timeouts, or similar events. As a result, certain blocked or denied access attempts may not appear on the Recent Activity page, making them difficult to trace. You can review sign-in activity here:

    • For a work or school (business) account:

    You can contact your IT administrator. They can access the Microsoft Entra Admin Center and review the user's Sign-in Logs as described in Step 2. These logs may provide additional details such as the source IP address, location, sign-in status, and other indicators that can help investigate suspicious access attempts.

    About the explaination for this situation, this activity can sometimes occur when an email address or username becomes exposed to automated traffic or repeated sign-in attempts online. As a result, the issue may continue even after a password change, although changing the password remains an important security measure. When an unauthorized sign-in attempt is made using your email, the system automatically sends a notification to your Microsoft Authenticator app as part of its security design. 


    Along the way, as an independent advisor, I can only recommend steps to strengthen your account security and reduce repeated notifications based on your account type.

    1/ If you are using personal account:

    You can set up an additional sign-in alias. These options help reduce unwanted sign-in attempts and provide an extra layer of protection.

    -Sign in to your Microsoft account 

    -Choose “Add email” 

    • Start adding a new alias (do not remove anything yet). 

    -Create a new email alias 

    • Use a strong, hard-to-guess address (e.g., random string). 
    • Set it as your primary login email 

    -Make the new alias your main sign-in address. 

    -Disable login for your old email 

    • This is critical, it blocks attackers from using the old address. 

    -Remove the old email alias if you no longer need it (Optional, last step)  

    For your reference: Change the email address for your Microsoft account | Microsoft Support

    I have attached screenshots to help you with the process:

    User's image

    2/ If you are using business account:

    You can reach out to your IT Admin, who has global administrative rights in your organization’s tenant, to help strengthen your account security and prevent repeated notifications by referencing this thread.

    Getting too many authentication attempts on my account - Microsoft Q&A

    If you still need my assistance, please come back with screenshots or any additional details so I can review it again and see if there’s anything more I can help you with.  

    Wishing you all the best!


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".  

    Note: Please follow the steps in "our documentation" to enable e-mail notifications if you want to receive the related email notification for this thread.

    Was this answer helpful?


  2. AI answer

    2026-07-06T23:13:19.8133333+00:00

    When an unexpected sign-in prompt appears in Microsoft Authenticator or Authenticator Lite (for example, in Outlook), it means someone or something is trying to use the account credentials.

    What can be seen about the request:

    • Authenticator notifications can include the sign-in location (city/region) to provide better sign-in security. This location comes from the phone’s operating system and can sometimes be approximate or slightly incorrect.
    • For unusual or anomalous sign-ins, starting August 2023, notifications might not be pushed automatically. In those cases, the pending request can be seen by opening Microsoft Authenticator (or Authenticator Lite in Outlook) and refreshing; the app will show the sign-in request details there.

    How concerned to be and what to do:

    1. Treat any unrequested prompt as potentially suspicious.
    2. Always select Deny if the prompt was not initiated personally.
    3. Check the account’s recent activity to confirm whether there are unfamiliar sign-ins or attempts. For personal Microsoft accounts, sign in to the Security basics page and use Review activity to inspect the Recent activity and Unusual activity sections.
    4. If any activity is not recognized, mark it as This wasn’t me or Secure your account as appropriate, then change the password to a strong, unique one.

    If repeated unrequested prompts appear, it indicates that someone has the username and is actively trying to sign in, so reviewing recent activity and updating password and security info should be treated as urgent.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.