Fremde Anmeldung in Authenticator App

Bulter GmbH 0 Reputation points
2025-01-25T17:46:11.6533333+00:00

Hallo,

ich bekomme von der Authenticator App immer wieder ein Anmeldeversuch, obwohl ich keine Anmeldung durchführe.

Ich habe den Verdacht, jemand Fremdes versucht auf meinen Account zu gelangen.

kann man das prüfen ?

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
23,104 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Vahid Ghafarpour 22,405 Reputation points
    2025-01-26T02:34:59.5333333+00:00

    It seems that someone is trying to access your account

    Make sure 2FA is enabled to provide an additional layer of security to your account.

    0 comments No comments

  2. Venkata Jagadeep 80 Reputation points Microsoft Vendor
    2025-01-29T09:53:50.2633333+00:00

    Hello Butler GmbH,

    Thank you for posting your query on Microsoft Q&A.

    As per your description, we understand that you are seeing sign-in attempts on your authenticator app.

    From Azure, we can prevent a bad actor to successfully sign-in with your user account, but we cannot stop him to attempt to sign-in.

    To prevent un-authorized sign-in attempts to reach second factor authentication, we suggest you identify from which IP address the bad user is attempting to sign-in. For that you can check the user sign-ins in azure portal.

    Once you get the IP Address of the bad actor, you can configure a Conditional Access Policy to block those Bad IP Addresses.

    In Azure portal - Security - Manage - Named Locations, please include all bad IP addresses and give it a name. (Ex : Bad IPs)

    While creating CA policy, under Network please exclude the Named Location (Bad Ips) and select block in grant access as shown below.

    capolicy1

    We strongly recommend using phishing resistant MFA method for all users to prevent unauthorised access.

    Reference

    https://learn.microsoft.com/en-us/entra/identity/conditional-access/policy-block-by-location

    And Microsoft recommends following Security Best Practices.

    Reference

    https://learn.microsoft.com/en-us/azure/security/fundamentals/identity-management-best-practices

    I hope this information is helpful. Please feel free to reach out if you have any further questions.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Thanks,

    Venkata Jagadeep


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.