A “we detected unusual sign-in activity” alert from Microsoft is triggered automatically by risk-detection algorithms โ most are legitimate warnings worth checking, but a meaningful share are false positives from travel or a new device, not an actual compromise.
Common Symptoms
- Email alert about a sign-in from an unfamiliar location or device
- “Unusual sign-in activity” notification when reviewing account activity
- A sign-in attempt you don’t recognize in the account’s activity log
Possible Causes
- Genuine unauthorized access attempt
- Sign-in from a new device, browser, or location you weren’t expecting (e.g. travel, new phone)
- A VPN exiting from an unusual geographic location
- A colleague or family member using a shared device/account inappropriately
Before You Begin
Check the exact timestamp, location, and device listed in the alert against your own recent activity before assuming the worst โ a lot of these alerts are explainable.
Method 1 โ Review recent sign-in activity
Open account sign-in activity
Go to your Microsoft account’s security/sign-in activity page and review recent entries for anything you don’t recognize.
Method 2 โ Change your password immediately if it looks real
Reset the password
If you don’t recognize the sign-in and it wasn’t you, change your password right away, from a device you trust.
Method 3 โ Enable or review MFA
Never click a link inside an unexpected security email โ navigate to your account settings directly by typing the address yourself, since phishing emails frequently imitate these exact alerts.
Frequently Asked Questions
How can I tell if a “security alert” email is real or phishing?
Don’t click any links in the email. Instead, open a new browser tab and go directly to your Microsoft account sign-in activity page โ if there’s a genuine alert, it will also appear there.
Conclusion
Reviewing sign-in activity directly (not via email links), resetting the password if needed, and enabling MFA covers the appropriate response to nearly every account security alert.