How can I block access attempts from outside my country?

Anonimo
2023-10-28T01:03:40+00:00

In my Microsoft account I continue to receive login attempts from suspicious countries (like China) and feel targeted by malicious people. I would like to be able to put a block on certain countries so that anyone who tries to access from those regions stays out. I looked online for how to apply "geoblocking" to my account but I couldn't find anything that easily explains how to do it (or that explains it at all). Or the steps require some admin authorization but I don't understand how to give myself admin permissions on the Microsoft Entra page. Microsoft support is not available either and I don't know how to contact them.

Can anyone help me?

Microsoft 365 e Office | Sottoscrizione, account, fatturazione | Per la casa | Altro

Domanda bloccata. Questa domanda è stata eseguita dalla community del supporto tecnico Microsoft. È possibile votare se è utile, ma non è possibile aggiungere commenti o risposte o seguire la domanda.

0 commenti Nessun commento

6 risposte

Ordina per: Più utili
  1. Anonimo
    2023-10-28T04:12:03+00:00

    #1 - Have described how to protect the email address that is the target which is not to allow it to be used as a login ID - can't add more to that. Trying to login using an email address that has been disabled as a login ID is not deemed as a login attempt. The described steps that you have taken are as much as you can do for an active account.

    Let me put this another way. I have multiple Outlook.com accounts and not one ever gets any spam and I am serious when I use the word "never". I can't say the same thing for a couple of my non-Microsoft accounts but by the same token, I don't use my Outlook.com accounts to sign up for anything so these addresses never get "harvested".

    #2 - Not having any recovery options on your account is almost a guarantee to not being able to being to recover an account should that become necessary. As for someone who gains access to your account seeing your recovery email addresses, each email account should be protected accordingly. The hacker would still need to know the password to the account in order to access it. If someone uses the same password everywhere, then yes, it's a dangerous scenario but one of their own making. So many people wonder how their social media accounts get hacked so easily when they use the same email address / password combination on all their accounts.

    @3 - microaoftoneline.com -for business accounts

    La risposta è stata utile?

    0 commenti Nessun commento
  2. Anonimo
    2023-10-28T03:46:13+00:00

    The you referenced is not a scam of any kind. As a FYI, any URL that ends with "micrsoft.com will always be a legitimate Microsoft URL. My apologies but I should have asked if this involves a consumer or business account. Information on Entra is contained in Cos'è Microsoft Entra ID? https://learn.microsoft.com/it-it/entra/fundamentals/whatis Assuming you are asking about a consumer account, what you have described is an email address that has been "harvested" and hackers are using the email address to try and log into your account. I have an article on how email addresses get harvested along with an additional step you can take to protect your account, but you will need to use your browser's translation function since it is only available in English Basics: Protecting your account https://answers.microsoft.com/en-us/msoffice/forum/all/basics-protecting-your-account/693aec43-a158-4b4f-ac7a-fe537cf3a4c3 If you have any other questions, please ask

    Mine is a consumer account. The email in question is from when I was a kid (I didn't have good IT or security knowledge) and was also subject to data breaches by some services. But I have long since updated the security of that and all other my accounts to the maximum (different complex passwords for each account/site/service, 2FA, phone numbers, backup codes...)

    So I get it: once an account becomes "harvested" you can only limit the damage.

    I have some final doubts:

    1. Due to too many unsuccessful login attempts from suspicious countries/devices, is there a risk that Microsoft will block my account? If so, what can be done to avoid it?
    2. Another Microsoft Login address is "login.microsoftonline.com". Is it still Microsoft or is it an imitator/scam?
    3. Isn't adding a recovery email risky? If they hack your email, they might see the other associated email address and have a new target or am I wrong?

    Thanks in advance

    La risposta è stata utile?

    0 commenti Nessun commento
  3. Anonimo
    2023-10-28T02:23:23+00:00

    The you referenced is not a scam of any kind. As a FYI, any URL that ends with "micrsoft.com will always be a legitimate Microsoft URL.

    My apologies but I should have asked if this involves a consumer or business account. Information on Entra is contained in

    Cos'è Microsoft Entra ID? https://learn.microsoft.com/it-it/entra/fundamentals/whatis

    Assuming you are asking about a consumer account, what you have described is an email address that has been "harvested" and hackers are using the email address to try and log into your account.

    I have an article on how email addresses get harvested along with an additional step you can take to protect your account, but you will need to use your browser's translation function since it is only available in English

    Basics: Protecting your account https://answers.microsoft.com/en-us/msoffice/forum/all/basics-protecting-your-account/693aec43-a158-4b4f-ac7a-fe537cf3a4c3

    If you have any other questions, please ask

    La risposta è stata utile?

    0 commenti Nessun commento
  4. Anonimo
    2023-10-28T02:05:39+00:00

    Hello INeedSupport41 Hi, I'm Karl and will be happy to help you today. First, just so there is no misunderstanding, this is a public user-to-user support forum. We're users helping other users. We do not work for Microsoft and have no input on Microsoft's policies, procedures, or design decisions. With that said, the reason you have not been able to find information on geo-blocking login attempts is because that option does not exist. If you have any questions, don't hesitate to ask, we're here to help you further if needed.

    So, is this "Microsoft Entra" a sort of scam? ( https://entra.microsoft.com/ )
    Because I first checked it on VirusTotal and it didn't find anything suspicious. When I tried to log in, it only required me an e-mail address (and nothing else). Should I worry? Or is it another Microsoft service of some sort?

    What's the best suggestion someone could give when there are many suspicious access/login attempts daily? (I have a strong password, 2FA, and whatnot but it gives me anxiety seeing this much "determination" in accessing it).

    La risposta è stata utile?

    0 commenti Nessun commento
  5. Anonimo
    2023-10-28T01:39:53+00:00

    Hello INeedSupport41

    Hi, I'm Karl and will be happy to help you today.

    First, just so there is no misunderstanding, this is a public user-to-user support forum. We're users helping other users. We do not work for Microsoft and have no input on Microsoft's policies, procedures, or design decisions.

    With that said, the reason you have not been able to find information on geo-blocking login attempts is because that option does not exist.

    If you have any questions, don't hesitate to ask, we're here to help you further if needed.

    La risposta è stata utile?

    0 commenti Nessun commento