A surprise sign-in prompt can mean someone knows your password, entered your address by mistake or is trying to wear you down. Never approve a request just to stop the notifications, and never share the displayed code with a caller.
MFA reduces risk, but an approval from you can still authorize a fraudulent sign-in. The safe habit is to compare the prompt with an action you started moments ago.
Respond in order
- Tap Deny or It's not me for a sign-in you did not start. Do not type a number from the prompt into a call or chat.
- Open the service directly and review recent account activity, signed-in devices and recovery methods. A failed attempt is different from a completed sign-in.
- Change the account password if there is suspicious activity or repeated prompts. Use a unique password and check whether it was reused elsewhere.
- If the service allows it, sign out unfamiliar sessions and replace an exposed or lost authenticator method. Keep another recovery method available before removing one.
Know when to escalate
A single request may be a typo. Repeated requests, a completed sign-in you do not recognize or changed recovery details need urgent account recovery. For a work or school account, tell your IT team; they can check logs and revoke sessions. Microsoft explicitly advises denying requests you did not initiate. Google gives similar unfamiliar-activity steps.MFA reduces risk, but an approval from you can still authorize a fraudulent sign-in. The safe habit is to compare the prompt with an action you started moments ago.