How to Protect Microsoft 365 Accounts from Repeated Login Attempts
Question details
An administrator needs to secure Microsoft 365 email accounts against multiple unauthorized sign-in attempts from suspicious IP addresses.

- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- A client's email accounts are facing continuous suspicious login attempts, and the administrator wants to reduce these attempts and properly secure the accounts.
- Observed behavior
- The accounts are receiving malicious-activity warnings and triggering account locks due to repeated login attempts from unfamiliar IP addresses.
Ensure you have global administrator or security administrator privileges in the Microsoft 365 admin center before attempting to configure conditional access policies or review sign-in logs.
Implement Multifactor Authentication (MFA) and Conditional Access
Use Microsoft Entra ID Conditional Access to enforce MFA and block suspicious login attempts based on location or device risk.
Conditional Access policies are the most effective way to reduce unauthorized login attempts. By defining specific conditions (like trusted IP ranges or known devices), you can automatically block high-risk logins before they even prompt for a password.
Log in to the Microsoft Entra admin center as a security administrator and navigate to 'Protection' > 'Conditional Access'.
Click 'New policy' and assign it to the affected users or groups that are experiencing the brute-force login attempts.
Under 'Conditions', select 'Locations'. You can configure this to block access from untrusted or unexpected countries and IP addresses.
Under 'Grant', select 'Require multi-factor authentication' to ensure that even if a password is compromised, the attacker cannot access the account.

Audit Sign-in Logs and Revoke Active Sessions
Investigate the source of the attacks and force-logout compromised or at-risk accounts across all devices.
Looking for a Secure and Free Office Suite? Try WPS Office
While securing your Microsoft 365 environment, consider WPS Office as a lightweight, highly compatible, and free alternative for your daily document creation needs. It offers a familiar interface, robust local file protection, and seamless migration.
- 1. Download the Installer: Visit the official WPS Office website and download the free installation package for your operating system.
- 2. Install WPS Office: Run the downloaded installer and follow the on-screen instructions to complete the setup process quickly.
- 3. Open Your Documents: Launch WPS Office and open your existing Microsoft Word, Excel, or PowerPoint files without worrying about formatting issues.

Frequently Asked Questions
Can attackers bypass Microsoft 365 two-factor authentication?
While traditional MFA is highly secure, sophisticated attackers can use phishing proxies (AiTM attacks) to intercept session tokens. It is recommended to use phishing-resistant authentication methods like FIDO2 security keys or Microsoft Authenticator with number matching enabled.
How do I completely block logins from specific countries in Microsoft 365?
You can block specific countries by setting up 'Named Locations' in Microsoft Entra ID. Once defined, create a Conditional Access policy targeting those locations and set the 'Grant' control to 'Block access'.
What should I do if a Microsoft 365 account is already compromised?
Immediately reset the user's password, revoke all active sessions in the Microsoft Entra admin center, check for hidden forwarding rules in Exchange Online, and follow Microsoft's official 'Responding to a Compromised Email Account' guidance to ensure the threat is fully neutralized.




