If someone is attempting to access your Microsoft account and the sign-in activity page only seems to show successful sign-ins, you still have options. Confirm whether the account is personal or work/school, keep denying unexpected MFA prompts, and use the correct activity or Entra log path for failed attempts.
Why the Sign-in Activity Page May Not Show Failed Sign-in Attempts
The objective is to view sign-in attempts that are not successful when someone is attempting access. Sign-in and login problems usually involve account identity, saved credentials, security information, or organization policy. Many users notice that the consumer-facing activity views emphasize successful or completed events, while repeated denials or automated probes are easier to investigate through Security activity details or—on work accounts—Microsoft Entra sign-in logs.
Quick Answer for Viewing Unsuccessful Sign-in Attempts
First confirm personal Microsoft account versus work/school (Microsoft 365 / Entra ID). Keep denying any Authenticator prompts you did not start. For personal accounts, sign in at account.microsoft.com, open Security / Security basics, and review Recent activity and Unusual activity thoroughly—including expandable details—not only the summary list. For work/school accounts, ask your IT administrator to open Microsoft Entra admin center Sign-in Logs filtered to failure statuses. Change your password, review forwarding rules, and ensure MFA remains enabled.
Possible Causes of Missing Failed Sign-in History
- Consumer Recent activity surfaces certain completed or notable events more clearly than every blocked probe.
- Personal and work/school portals show different log depth; Entra logs are admin-only for organizational accounts.
- Email addresses exposed in leaks attract automated sign-in attempts from many countries.
- You are signed into a different Microsoft identity than the one receiving the attacks.
- Saved credentials or outdated security info make it harder to interpret which account is targeted.
Recommended Solution: Choose the Right Activity Path for Personal or Work Accounts
When to use this: Use this when you deny multiple access attempts daily and need better visibility than a success-only activity summary.
- Confirm you can still access the account. If locked out, use Microsoft account recovery or your IT helpdesk before changing security settings.
- Identify account type: personal (Outlook.com, Hotmail, live.com) versus work/school Microsoft 365 / Entra ID.
- For personal accounts, open Security basics, use Review activity, and inspect Recent activity and Unusual activity; expand entries for IP, approximate location, and status where shown.
- For work/school accounts, contact IT so they can review Sign-in Logs (failure filters, IP, location, client app, conditional access results).
- Change the password on the targeted account, revoke suspicious sessions if the portal offers that control, and keep MFA on with a backup method.
- Expect some automated attempts to continue after a password change if the email address remains publicly exposed; keep denying prompts and monitoring logs.
Why this works: Matching the investigation path to account type surfaces failure detail that the simplified success-focused view may hide, while password and MFA steps reduce successful compromise risk.
If this fails: Escalate to Microsoft support (personal) or your administrator (work) with timestamps of denied MFA prompts. Never share passwords or codes with unsolicited callers.
Additional Fix: Harden the Account When Attempts Come From Many Countries
When to use this: Use this when failed or denied attempts appear from unfamiliar regions and you want fewer successful risks even if probes continue.
- Enable Authenticator number matching or passwordless sign-in if available for your account type.
- Remove unknown devices, apps, and old MFA methods from security settings.
- Check inbox rules and forwarding for unauthorized changes after any successful unfamiliar sign-in.
- If a work account is targeted, ask IT whether conditional access or blocked sign-in policies can reduce noisy failures.
Why this works: Stronger MFA and session cleanup limit damage when usernames are widely tried by bots.
If this fails: Keep documenting attempt times for support; do not disable MFA to stop notifications.
Keep Editing Documents Locally With WPS Office During Account Security Checks

WPS Office cannot display Microsoft failed sign-in logs, reset Microsoft accounts, manage Authenticator, or change Entra policies. Activity investigation stays with Microsoft portals and your IT administrators.
While you review security activity, WPS Office can help you continue local document work:
- Download and install WPS Office.
- Open local Word, Excel, PowerPoint, or PDF copies in WPS apps.
- Edit and save offline so work continues during password and MFA hardening.
- Return to Microsoft 365 after activity reviews and security changes look complete.
This limits disruption when investigating attempted access. If you need an Office-compatible suite during the security checkup, try WPS Office.
Prevention Tips for Unauthorized Sign-in Attempts
- Use a unique password and never approve unexpected MFA prompts.
- Review personal Unusual activity or ask IT to watch Entra failure spikes after phishing or data-breach news involving your address.
- Keep recovery email and phone current so you can regain access if attacks escalate.
- Separate personal and work Microsoft identities; do not reuse the same password across them.
- Prefer phishing-resistant MFA where your organization supports it.
FAQs About Viewing Failed Sign-in Attempts
Why does activity only show successful sign-ins?
Consumer views can emphasize successful or notable events. Expand Unusual activity details, and for work accounts ask IT to use Entra Sign-in Logs with failure filters.
Should I worry about attempts from other countries?
Repeated automated probes are common when an email is exposed. Deny MFA prompts, change the password, and monitor; escalate if any unfamiliar sign-in succeeds.
Can WPS Office show Microsoft sign-in attempt history?
No. WPS Office cannot access Microsoft account or Entra logs; it only helps you edit local files while you secure the account.




