People from other countries trying to login into my hotmail. I have auth login, so I see the countries they are sending from.

David Kurbanov 20 Reputation points
2026-07-27T10:34:47.7833333+00:00

How can I block user from different countries to login? What could I do instead? Im getting the auth notification several times each day, maybe 20-30 times.

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-07-27T10:35:10.1566667+00:00

    There is no supported way in the provided guidance to block Microsoft account sign-ins by country for a personal Hotmail/Outlook.com account.

    What can be done instead:

    1. Review the sign-in attempts on the Recent activity page.
      • Expand the unusual activity entries.
      • If an attempt was not recognized, select This wasn't me.
      • That starts account protection steps, including changing the password and updating security info.
    2. Keep multi-factor verification enabled.
      • Unsuccessful sign-in attempts from other countries do not mean the account was accessed.
      • Microsoft may also flag legitimate travel, a new device, or a new app sign-in as unusual.
    3. Add a new alias and block the old alias from sign-in.
      • This is the most relevant workaround for repeated Authenticator prompts when attackers know the current sign-in address.
      • Go to the Microsoft account site, then Your info > Sign-in preferences.
      • Add a new alias, then allow sign-in only for that alias and save.
      • The older address can remain on the account for email, but it no longer needs to be allowed for sign-in.
    4. If verification is temporarily blocked, avoid repeated retries.
      • Try another verification method connected to the account.
      • Try another network.
      • Wait up to 24 hours, and in some cases longer, up to 1 week.
    5. Make sure security contact info is current.
      • Keep the alternate email address or phone number updated so security codes can be received when Microsoft detects unusual activity.

    If the notifications are happening 20–30 times a day, the strongest supported mitigation in the provided guidance is to change which alias is allowed to sign in. That reduces the value of the exposed sign-in address while keeping the account and mailbox.

    Also verify suspicious alerts carefully. A legitimate unusual sign-in email is identified in the guidance as coming from ******@accountprotection.microsoft.com.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.