Someone is loggin in into my account from different location.

MABORE SWAFO 0 Reputation points
2025-03-10T12:07:24.7933333+00:00

Someone is signing in into my account and authenticator app even though i changed my password several times.

Microsoft Entra
0 comments No comments
{count} votes

Accepted answer
  1. Sakshi Devkante 1,335 Reputation points Microsoft External Staff
    2025-03-12T07:11:22.6233333+00:00

    Hello Mabore,

    Based on your description, I understand that your Microsoft account may be under attack, you have enabled Two-Factor Authentication (2FA) for your Microsoft account, which should prevent unauthorized access. it's possible someone has gained your account credentials.  I recommend taking additional steps to further secure your account.

    If your password has been repeatedly leaked, it's possible that it may be weak or easily guessable. Please ensure you create a strong, unique password that has not been used elsewhere. Consider using a password manager to generate and store complex passwords. change your password and update security settings You can do that on the Security settings page, where you can also remove all trusted devices. To learn more about account management and security, see Security basics

    In addition, for the security of your account, please refer to the methods mentioned in this document to protect your account and strengthen its resilience to attacks. How to help keep your Microsoft account safe and secure - Microsoft Support.

    More information: Check the recent sign-in activity for your Microsoft account.  

    Also, wanted to check if you have leveraged risk policies and conditional access policies as an option. you can set up device base and location base conditional access policy for more security please do refer this policy in below document.
    Location based Conditional access policy
    Device Based Conditional access policy

    Refer to this link for more detailed information - https://learn.microsoft.com/en-us/azure/active-directory/identity-protection/howto-identity-protection-configure-risk-policies

    Enable sign-in risk policy for MFA - https://learn.microsoft.com/en-us/azure/active-directory/authentication/tutorial-risk-based-sspr-mfa#:~:text=Enable%20sign%2Din%20risk%20policy%20for%20MFA

    Check the recent activity section of your Microsoft account for any unauthorized access or changes. Report any suspicious activity to Microsoft. 

    Secure Your Email Account since email accounts are often used for password recovery, ensure that your email account is secured with 2FA as well. Be cautious of phishing emails or messages that may attempt to trick you into revealing sensitive information or login credentials. 

    I hope this clarifies things.

    Please remember to "Accept Answer", so that others in the community facing similar issues can easily find the answers.

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.