Unauthorized Sign in attempts

Susan Klaiber 0 Reputation points
2026-08-04T00:39:57.86+00:00

What to do about multiple unauthorized sign in attempts after changing password?

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-08-04T00:40:14.4633333+00:00

    If the attempts are still happening after a password change, the account is usually still being targeted, but the repeated attempts do not mean the attacker got in.

    For a work or school account:

    1. Check recent sign-in activity
      • Go to My Account at https://myaccount.microsoft.com/.
      • Select Recent Activity.
      • Review the entries for unfamiliar locations, browsers, operating systems, or apps.
      • If something looks unfamiliar, change the password again and update security settings on the Security info page.
    2. Look for MFA-related failures
      • If an entry says "Additional verification failed, invalid code", the password may have been guessed but the two-step verification challenge was not completed.
      • In that case, Microsoft recommends changing the password and updating security settings at https://mysignins.microsoft.com/security-info.
    3. If repeated sign-in attempts trigger a block
      • Microsoft Entra multifactor authentication can temporarily prevent more attempts after unusual repeated sign-ins.
      • Wait until sign-in is allowed again, or use a different MFA method.
      • If the activity is not recognized, contact the IT administrator and ask them to review the Microsoft Entra sign-in logs.
    4. Keep MFA enabled
      • Two-step verification helps prevent access even if someone knows the password.

    For a personal Microsoft account:

    1. Go to the Security basics page at https://account.microsoft.com/security.
    2. Select Review activity and inspect the Recent activity page.
    3. If activity is not recognized, select This wasn't me or Secure your account where available.
    4. Change the password again from the Security basics page if suspicious activity appears.

    If the issue is specifically constant Authenticator prompts, accepted Microsoft Q&A guidance says this often happens because the sign-in name is exposed. For personal accounts, one mitigation is to create a new alias, make it the primary sign-in alias, and disable sign-in for the old exposed alias so attackers can no longer use the old sign-in name. For business accounts, an administrator may need to help with alias changes and tenant protections.


    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.