logo
search
Suspicious Login Issues

How to Protect Microsoft 365 Accounts from Repeated Login Attempts

Algirdas JasaitisAlgirdas Jasaitis Sep 25, 2026 869 views

Question details

An administrator needs to secure Microsoft 365 email accounts against multiple unauthorized sign-in attempts from suspicious IP addresses.

How to Protect Microsoft 365 Accounts from Repeated Login Attempts
Product
Microsoft 365
Device & OS
not provided
Scenario
A client's email accounts are facing continuous suspicious login attempts, and the administrator wants to reduce these attempts and properly secure the accounts.
Observed behavior
The accounts are receiving malicious-activity warnings and triggering account locks due to repeated login attempts from unfamiliar IP addresses.
Before you start

Ensure you have global administrator or security administrator privileges in the Microsoft 365 admin center before attempting to configure conditional access policies or review sign-in logs.

Solution 1Recommended

Implement Multifactor Authentication (MFA) and Conditional Access

Use Microsoft Entra ID Conditional Access to enforce MFA and block suspicious login attempts based on location or device risk.

Conditional Access policies are the most effective way to reduce unauthorized login attempts. By defining specific conditions (like trusted IP ranges or known devices), you can automatically block high-risk logins before they even prompt for a password.

1
Access Microsoft Entra ID

Log in to the Microsoft Entra admin center as a security administrator and navigate to 'Protection' > 'Conditional Access'.

2
Create a New Policy

Click 'New policy' and assign it to the affected users or groups that are experiencing the brute-force login attempts.

3
Configure Location Conditions

Under 'Conditions', select 'Locations'. You can configure this to block access from untrusted or unexpected countries and IP addresses.

4
Enforce MFA

Under 'Grant', select 'Require multi-factor authentication' to ensure that even if a password is compromised, the attacker cannot access the account.

Implement Multifactor Authentication (MFA) and Conditional Access
Enhanced Security: Using phone-based verification or the Microsoft Authenticator app makes unauthorized sign-ins significantly more difficult and is highly recommended for all users.
Free Microsoft Office alternative

Looking for a Secure and Free Office Suite? Try WPS Office

While securing your Microsoft 365 environment, consider WPS Office as a lightweight, highly compatible, and free alternative for your daily document creation needs. It offers a familiar interface, robust local file protection, and seamless migration.

  1. 1. Download the Installer: Visit the official WPS Office website and download the free installation package for your operating system.
  2. 2. Install WPS Office: Run the downloaded installer and follow the on-screen instructions to complete the setup process quickly.
  3. 3. Open Your Documents: Launch WPS Office and open your existing Microsoft Word, Excel, or PowerPoint files without worrying about formatting issues.
100% compatible with Microsoft Office formats (.docx, .xlsx, .pptx)Free and lightweight alternative to Microsoft 365Familiar, intuitive user interface for seamless migrationRobust local document encryption and protection features
microsoft office alternative - wps office

Frequently Asked Questions

Can attackers bypass Microsoft 365 two-factor authentication?

While traditional MFA is highly secure, sophisticated attackers can use phishing proxies (AiTM attacks) to intercept session tokens. It is recommended to use phishing-resistant authentication methods like FIDO2 security keys or Microsoft Authenticator with number matching enabled.

How do I completely block logins from specific countries in Microsoft 365?

You can block specific countries by setting up 'Named Locations' in Microsoft Entra ID. Once defined, create a Conditional Access policy targeting those locations and set the 'Grant' control to 'Block access'.

What should I do if a Microsoft 365 account is already compromised?

Immediately reset the user's password, revoke all active sessions in the Microsoft Entra admin center, check for hidden forwarding rules in Exchange Online, and follow Microsoft's official 'Responding to a Compromised Email Account' guidance to ensure the threat is fully neutralized.