Knowledge Base / Accounts / Suspicious Sign-In Warning
Problem
Practical checks for suspicious sign-in warning. Follow the safe steps below and contact your support team if the issue continues.
These are general troubleshooting checks, not a confirmed diagnosis. Follow your organization's procedures and stop if a step could risk data, safety, or managed equipment.
Symptoms to check
- You receive a sign-in alert from an unknown country, device, or browser.
- The issue may affect one account or a group of users if a shared service is under attack.
Possible causes
- Someone may have guessed or reused a password, or the sign-in activity is being triggered by a compromised session.
- A spoofed email or malicious app may be attempting to access the account.
Resolution
- If you did not sign in, mark the activity as suspicious and follow the official reset process from the official service website.
- Check recent activity for unknown devices and sign-out all sessions if the service offers that option. Change the password only after confirming the account is safe.
- Review whether the user recently clicked a phishing message or reused a password across another account. If so, also check other services and reset any shared credentials.
- Update security settings, including MFA, recovery email, and device trust. Only use the official sign-in portal from a trusted device.
- Escalate to the administrator or support team with the date and time of the sign-in alert and any suspicious associated device or location information.
Prevention and preparation
- Use a unique password and enable MFA on all business accounts.
- Review sign-in alerts promptly so a small issue does not become a larger account compromise.
Related guides
Still not fixed? Log a support request and include the exact error, who or what is affected, and the steps you already tried. Never include passwords or verification codes.
Submit a ticketLast reviewed: October 2026