A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Unsuccessful sign-in attempts from many locations do not mean attackers are getting into the account. Anyone who knows the email address can try to sign in from anywhere, but with a strong password and two-step verification enabled, the account is better protected.
What to do next:
- Check recent sign-in activity.
- Go to the My sign-ins page in the Microsoft account portal and review the activity.
- Look for whether the attempts are successful or unsuccessful.
- If they are unsuccessful, that indicates the protection is working.
- If any sign-in is successful and not recognized, change the password immediately.
- Then update security settings in Security info.
- Be careful interpreting location data.
- Microsoft notes that location is approximate and can be inaccurate, especially on mobile networks.
- Review the browser, operating system, and app details too, not just the map location.
- Make sure multiple verification methods are available.
- Keep more than one verification method configured so sign-in and recovery remain possible.
- If repeated sign-in attempts continue, keep monitoring rather than expecting Microsoft to block every external IP.
- The context supports reviewing sign-in history and securing the account with password and MFA, but does not describe a user option to block individual attacker IP addresses for a personal Outlook/Microsoft account.
If there are sign-in problems, blocks, or unusual activity warnings:
- Try another verification method if one is blocked.
- Avoid repeated attempts, because high-volume retries can trigger temporary blocks.
- If needed, use the Microsoft sign-in helper.
References: