Try this first
- 1Approve nothing. Close the Authenticator app, let the pushes pile up.
- 2Change your password from another device. The attacker already has the old one, that is why the spam is happening.
- 3Turn on number matching for your tenant (Entra > Security > Authentication methods > Microsoft Authenticator). Forces typing a number, blind approval becomes impossible.
- 4Check Entra sign-in logs for the timestamps. Record IP and country for the incident report.
- 5Tell IT even if you approved nothing. Often part of a broader campaign against multiple colleagues.
When to bring us in
Did you accidentally approve: treat as account takeover. Revoke sessions, check mailbox rules, call us for log analysis.
See also
- I think I clicked a phishing linkNo shame, happens to everyone. The next fifteen minutes matter.
- A colleague's account is acting strangelySending mail in their name, rules hiding folders, unusual sign-ins. Suspicious.
- Lost the MFA app: new phone, no backup codesClassic problem after a phone upgrade. You are not the first to be locked out.
None of the above fits?
Describe your situation below. We pass your input plus the steps you already saw to our AI and return tailored next-step advice. If it's too risky to DIY, we'll say so.
Or skip the DIY entirely
Our Managed IT clients do not look these things up. One point of contact, a fixed monthly price, resolved within working hours.