How to Stop Repeated Microsoft Account Unusual Activity Alerts
Question details
The user is continuously receiving Microsoft unusual account activity alerts (such as sign-ins from Brazil) even after resetting their password, and needs to know how to properly secure the account and stop the alerts.

- Product
- Microsoft Account
- Device & OS
- Android (Samsung Galaxy S21 Ultra)
- Scenario
- Trying to identify the source of repeated suspicious login attempts and properly secure the account to stop the constant security notifications.
- Observed behavior
- The Microsoft account continues to trigger unusual activity alerts despite a recent password change, suggesting ongoing unauthorized login attempts or persistent legacy sessions.
Before taking action, verify that the alerts are genuinely from Microsoft (sent from account-security-noreply@accountprotection.microsoft.com) and not phishing emails attempting to steal your new password.
Review Sign-in Activity and Enforce Two-Step Verification
Checking your actual sign-in logs and forcibly signing out all devices ensures that any lingering unauthorized sessions are terminated.
Even after changing your password, old sessions on mobile apps or email clients might continue to attempt to sync, or automated bots might be spamming your email with login requests. Securing the account from the official Microsoft dashboard is essential.
Navigate to the official Microsoft Account Security page (account.microsoft.com/security) and log in with your credentials.
Click on 'Sign-in activity' to view the locations, IP addresses, and statuses (Successful or Unsuccessful) of recent logins to confirm if the activity from Brazil was actually successful.
Return to the Security dashboard, click 'Advanced security options', scroll down to the bottom of the page, and select 'Sign me out' to terminate sessions on all devices.
In the same 'Advanced security options' menu, find the 'Two-step verification' section and toggle it on. Follow the prompts to link an authenticator app or phone number.

Identify Account Type and Contact Administrator
If you are using a Microsoft 365 work or school account, your organization's IT department manages your security policies and can block suspicious IP addresses.
Work Securely Offline with WPS Office
If recurring Microsoft account security issues are interrupting your workflow or locking you out of Microsoft 365, you can switch to WPS Office. It provides a secure, lightweight, and offline-capable alternative without forcing continuous cloud logins.
- 1. Download the software: Visit the official WPS Office website and download the free desktop application for your operating system.
- 2. Install and open: Run the installer. Once opened, you can immediately start using Writer, Spreadsheets, and Presentation without needing to sign into a cloud account.
- 3. Edit Microsoft files locally: Drag and drop your existing .docx, .xlsx, or .pptx files into the WPS interface to securely edit your documents offline.

Frequently Asked Questions
Why do I keep getting unusual activity alerts after changing my password?
Attackers or automated bots might still be trying to log in using your email address and old passwords. If the sign-in attempts on your 'Sign-in activity' page say 'Unsuccessful', your password change worked, and your account is secure. The alerts are simply notifying you of the blocked attempts.
How can I tell if a Microsoft unusual activity email is real?
Genuine Microsoft account security emails are always sent from 'account-security-noreply@accountprotection.microsoft.com'. Check the actual sender address, not just the display name. If it comes from any other address, it is a phishing scam and you should not click any links in it.
Can I block sign-in attempts from specific countries?
For personal Microsoft accounts, you cannot block specific countries directly. However, you can create a new email alias, set it as your primary sign-in preference, and disable sign-in permissions for the email address that attackers are currently targeting.
Does an unusual sign-in activity alert mean I was hacked?
Not necessarily. It means someone (or a bot) attempted to sign in from an unrecognized device or location. Unless the activity log explicitly states 'Successful sign-in', the unauthorized party did not gain access to your account.




