Knowledge Base / Security / Suspicious Sign-In Warning
Problem
A user sees a message saying that a sign-in attempt was blocked or suspicious, and the user is unsure whether an unauthorized login occurred.
Suspicious sign-in alerts are an early warning sign of a compromised account or attacker activity. Validate the event, block risky access, and protect the account immediately.
Symptoms to check
- Microsoft or security alerts show sign-ins from a new location, device, or country.
- User receives a verification, blocked sign-in, or risky sign-in notification.
- Access was denied or the user saw unusual MFA prompts.
Possible causes
- Credentials were exposed or reused on a risky site.
- A user is traveling, using a VPN, or working from a different IP address.
- An unauthorized actor attempted to access the account.
Resolution
- Review the alert details, including the location, device, time, and the exact app or service that triggered the warning.
- Ask the user whether they recently signed in from a new device, location, or mobile network. Confirm whether the activity is expected.
- If the activity is not expected, reset the password, review recent sign-ins, and enforce MFA or a security challenge to confirm the user is the legitimate owner.
- Check whether other accounts or devices are affected, especially if the same credentials were reused elsewhere.
- Escalate to the security team if the user reports the account was accessed, a password was reused, or there are repeated warnings tied to the same user.
Prevention and preparation
- Encourage users to review sign-in alerts and report them immediately.
- Use MFA and password hygiene policies to reduce credential reuse risks.
- Document the suspicious sign-in workflow to keep user response consistent.
Related guides
Still not fixed? Escalate if the sign-in is confirmed as unauthorized or a password reset is already required due to repeated risky login attempts.
Submit a ticketLast reviewed: October 2026