2FA doesn't stop sign-in attempts, however, the potential intruders have a hard time gaining access to your account. Usually, after so many unsuccessful sign-in attempts at the same time, the system will suspend your account to stop an intruder from launching more sign-in attempts
However, please be informed if you still use 2FA SMS, I personally don't recommend it due to SIM swap attacks hackers often use nowadays. I discussed more about SIM swap attacks in the following article: https://answers.microsoft.com/en-us/msteams/for...
Last but not least, it's also important to understand where those attackers have harvested the email addresses. It's often because the users are a victim of a data breach from one of the websites you subscribe to. In my previous post, I've explained more about that topic and what you should do about it. So please visit In the following article: https://answers.microsoft.com/en-us/outlook_com...
Kind Regards