A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
There is no supported way in the provided guidance to block Microsoft account sign-ins by country for a personal Hotmail/Outlook.com account.
What can be done instead:
- Review the sign-in attempts on the Recent activity page.
- Expand the unusual activity entries.
- If an attempt was not recognized, select This wasn't me.
- That starts account protection steps, including changing the password and updating security info.
- Keep multi-factor verification enabled.
- Unsuccessful sign-in attempts from other countries do not mean the account was accessed.
- Microsoft may also flag legitimate travel, a new device, or a new app sign-in as unusual.
- Add a new alias and block the old alias from sign-in.
- This is the most relevant workaround for repeated Authenticator prompts when attackers know the current sign-in address.
- Go to the Microsoft account site, then Your info > Sign-in preferences.
- Add a new alias, then allow sign-in only for that alias and save.
- The older address can remain on the account for email, but it no longer needs to be allowed for sign-in.
- If verification is temporarily blocked, avoid repeated retries.
- Try another verification method connected to the account.
- Try another network.
- Wait up to 24 hours, and in some cases longer, up to 1 week.
- Make sure security contact info is current.
- Keep the alternate email address or phone number updated so security codes can be received when Microsoft detects unusual activity.
If the notifications are happening 20–30 times a day, the strongest supported mitigation in the provided guidance is to change which alias is allowed to sign in. That reduces the value of the exposed sign-in address while keeping the account and mailbox.
Also verify suspicious alerts carefully. A legitimate unusual sign-in email is identified in the guidance as coming from ******@accountprotection.microsoft.com.
References: