Resource icon

A Microsoft sign-in alert arrived. Was it really you?

A sign-in alert can reflect your own travel, a new browser, a failed password attempt or somebody reaching your account. The place shown may be approximate. An email about unusual activity is a prompt to inspect the account, not evidence by itself that someone got in.

Check the record​

  1. Type account.microsoft.com/security into your browser and open Recent activity. Do not use the alert's link or phone number.
  2. Expand the entry and compare the time, device, app and type of activity. A failed attempt is different from a successful sign-in or changed security details.
  3. If Microsoft offers This wasn't me for unusual activity, use it when appropriate. Review recovery information and active sessions; change your password if the activity is suspicious.

What the log can and cannot prove​

Microsoft says Recent activity may show significant events rather than every account action. A city mismatch alone is weak evidence; a completed sign-in from an unfamiliar device or a changed recovery method is stronger. Its activity guide explains event types. For work or school accounts, use your organization's security process; the personal-account dashboard may not apply.

After the first review​

If you find a successful sign-in you cannot explain, secure the account, then inspect security info and recent email activity. If the record contains only failed password attempts, a password change may still be sensible when it is reused, but failed attempts alone do not establish that someone entered the account.
Posted by
Jack
Views
1
First release
Last update

Ratings

0.00 star(s) 0 ratings

More resources from Jack