How to Investigate an Unexpected Microsoft Security Information Replacement Alert
Question details
The user received an SMS alert stating their security information was replaced and noticed account activity from an unfamiliar device with a private IP address (starting with 10). They need to determine the source of this activity.
- Product
- Microsoft Account / Microsoft 365
- Device & OS
- not provided
- Scenario
- Responding to an unexpected SMS alert regarding account security information replacement.
- Observed behavior
- The account logs display suspicious login activity from an unfamiliar device using a private IP address (10.x.x.x).
Do not ignore unexpected security alerts. Verify the legitimacy of the SMS notification by manually navigating to your Microsoft account security page in a browser, rather than clicking any links provided in the message.
Secure Your Account and Review Sign-in Activity
Take immediate action to lock down your account and review the unauthorized changes, as a private IP (10.x.x.x) can indicate VPN, corporate, or internal network activity.
An IP address starting with 10 is a private, non-routable IP address. In sign-in logs, it may represent a local corporate network, a VPN connection, or an internal Microsoft service routing. Because the log alone cannot pinpoint the exact source or user, you must treat this event as a potentially unauthorized access attempt.
Log in to your Microsoft account's security page and update your password to instantly sign out unauthorized users and prevent further access.
Navigate to the 'Advanced security options' section of your account. Remove any unfamiliar phone numbers or email addresses that were added as recovery methods.
Turn on two-step verification using a dedicated authenticator app or your verified phone number to add an extra layer of protection against future attacks.
Go to the 'Recent activity' page in your Microsoft account dashboard to identify any other suspicious sign-ins, locations, or unfamiliar devices.
Try WPS Office for a Secure and Lightweight Document Experience
Dealing with Microsoft account security and recovery can be stressful. If you want a reliable, offline-capable office suite that does not strictly depend on complex cloud account setups, WPS Office is an excellent free alternative. It offers a familiar interface and seamless compatibility with all your existing Microsoft Office files.
- 1. Download WPS Office: Visit the official WPS website and download the free installation package for your operating system.
- 2. Install the application: Run the installer and follow the brief on-screen instructions to complete the setup process.
- 3. Open and edit your files: Launch WPS Office and instantly open your existing Microsoft Office documents without needing to sign in to a cloud account.

Frequently Asked Questions
Why does my Microsoft sign-in log show an IP address starting with 10?
IP addresses starting with 10 (e.g., 10.0.0.1) are private, internal network addresses. In Microsoft logs, this usually indicates that the internet traffic was routed through an internal corporate network, a VPN, or a localized proxy service before reaching Microsoft's servers.
What should I do if my Microsoft security information was replaced by someone else?
You should immediately log in to your account, cancel the pending security information replacement request if the 30-day wait period is active, change your password, and enable two-step verification. If you cannot log in, use the official Microsoft account recovery form.
Can I track the exact location of a 10.x.x.x IP address?
No. Because these are private IP addresses used exclusively within internal networks, they do not have a public geolocation. Only the network administrator managing that specific internal network or VPN can trace the exact device.
How can I contact Microsoft Support for suspicious login activity?
You can visit the Microsoft Support website to open a ticket. If you are a business user, it is highly recommended to ask your organization's IT administrator to review your sign-in history and open a support ticket on your behalf via the Microsoft 365 Admin Center.




