My Service Support

How to Check Microsoft Login Attempts

Updated 2026-08-25 · 927 words

Be the first to rate this page

To check Microsoft login attempts, open the company’s official website, sign in, and select Security, then Sign-in activity or Recent activity. Review each Microsoft account sign-in attempt and report any entry you do not recognize.

The activity page records recent security events for the account. Use it as a warning and investigation tool, but remember that location and device details can be approximate.

Where can I view Microsoft login attempts?

  1. Open the company’s official website and sign in with the Microsoft account you want to review.
  2. Select Security from the account menu.
  3. Complete identity verification if Microsoft requests it.
  4. Open Sign-in activity or Recent activity to view recent Microsoft login attempts.

Before entering a password or verification code, confirm that the browser identifies the page as a genuine Microsoft site. Do not continue if the address is misspelled, the browser displays a security warning, or the page opened from an unexpected message and asks for unusual information.

A safer approach is to open Microsoft’s site yourself instead of using a link in an unsolicited email or text. Microsoft may require another verification step before showing sensitive security details.

What information appears with recent Microsoft sign-in attempts?

Each activity entry describes a sign-in attempt or another security event. Open an entry to see the available details, which may include:

  • The date and time of the attempt.
  • An estimated country, region, or location.
  • The device or operating-system type.
  • The browser or app associated with the request.
  • The IP address, which identifies the internet connection used for the attempt.
  • Whether the sign-in succeeded, failed, or required another security check.

A failed attempt means the account was not accessed through that attempt. It can still be important if the time, device, or pattern is unfamiliar because it may show that someone tried to use the account credentials.

The list may also contain routine account activity that is not an interactive login, such as an app checking mail or another Microsoft service reconnecting. Read the event description and expanded details before deciding what happened.

How do I check unfamiliar Microsoft login attempts?

  1. Open the unfamiliar entry and note its time, result, device, browser, location, and IP address.
  2. Compare the time with your own activity and with devices or apps that use the same Microsoft account.
  3. Consider whether you were traveling, using mobile data, connected through a workplace network, or using a privacy service that could change the displayed location.
  4. Check whether a familiar email app, game console, computer, or other Microsoft service recently asked you to sign in again.
  5. If the event still cannot be explained, treat it as suspicious and use the reporting option shown with the entry.

Location is estimated from an IP address and may identify the internet provider’s routing point rather than the device’s exact position. Browser and device labels can also be broad or incorrect. No single detail proves who made a Microsoft account login attempt; the time, result, and surrounding account changes provide useful context.

How do I report a Microsoft sign-in attempt that was not mine?

Open the unrecognized activity entry and select the option indicating that the activity was not yours or that you do not recognize it. Follow Microsoft’s account-protection prompts exactly as displayed.

The prompts may ask you to verify your identity, review account information, or update security settings. Use a device you trust, and do not approve a notification or provide a verification code unless you initiated the request.

If an entry says the sign-in was successful, act promptly. Also treat unexpected password changes, unfamiliar security information, sent messages you did not write, or repeated verification prompts as possible signs of account access.

How can I secure a Microsoft account after suspicious activity?

  1. Change the Microsoft account password to a new, unique password that is not used on another service.
  2. Review security information, including recovery email addresses, phone details, and verification methods. Remove only information you know is unauthorized.
  3. Enable two-step verification, which requires a second form of identity confirmation in addition to the password.
  4. Use Microsoft’s security controls to sign out of sessions or devices you do not trust, when that option is available.
  5. Review connected apps, account aliases, forwarding settings, and other security-sensitive changes for anything unfamiliar.
  6. Update the password anywhere the same password was reused, starting with the email account used for recovery.

Save any replacement recovery method before removing an old one, when possible. Security-information changes can affect the ability to receive codes, so read every warning Microsoft displays before confirming a change.

What should I do if I cannot sign in or receive a verification code?

If the password is rejected, use Microsoft’s password-reset option on the sign-in page. Enter the account identifier carefully and choose a verification method that you can access.

If a verification code never arrives:

  1. Confirm that the displayed destination matches a phone number or email address you control.
  2. Check spam or junk folders when the code is sent by email.
  3. Request a new code only through Microsoft’s sign-in process, then use the most recently received code.
  4. Try another verification method offered on the screen.
  5. Do not share the code with anyone, including someone claiming to provide support.

If none of the listed verification methods is accessible, choose the account-recovery option presented by Microsoft. Provide accurate information that helps establish ownership; do not guess repeatedly or submit another person’s information.

If you believe the account was compromised, begin with Microsoft’s compromised-account or recovery flow. After access is restored, check Microsoft login attempts again, change the password, review security information, enable two-step verification, and remove unfamiliar sessions or settings.

Was this page helpful?

Be the first to rate this page