What to Do If You Get a Sign-In Approval Request You Didn't Ask For
For anyone who got a push notification, text code, or authenticator prompt they did not initiate. This guide walks you through the fastest safe response: deny the request, secure your account, and verify there is no active unauthorized access.
TL;DR — If you get a sign-in approval request you did not ask for, do not approve it. Deny the request if your app offers that option, then immediately change your password from the service's website or app, sign out of other sessions, and review recent sign-in activity. If you reused that password anywhere else, change it there too. Reading time: ~5 min
Goal
When you finish, the unexpected sign-in request is denied, your account password is changed, other active sessions are signed out, and your recent account activity shows no ongoing unauthorized access.
Prerequisites
- Access to the account that received the unexpected sign-in request
- Access to your email inbox for that account
- Access to your phone if you use an authenticator app (an app that generates or approves sign-ins)
- Your current password, if you still know it
- A new unique password ready to use, or a password manager (an app that stores passwords securely)
- Access to the service's website or mobile app
- If available, access to the account security page in your provider's dashboard (for example: Account → Security, Settings → Security, or Profile → Login & Security)
Steps
Step 1: Do not approve the request
If the prompt is still on screen, tap the literal option that rejects it. Common labels are:
Deny
No, it's not me
Reject
Cancel
If there is no deny button, close the notification and do not enter any code anywhere.
What you should see when this succeeds: the approval prompt disappears, or the app shows that the sign-in was denied or expired.
Step 2: Go to the account security page from the official site or app
Open the service directly using the normal website or app you already use. Do not tap links in the unexpected notification, text, or email.
Use your provider's dashboard and go to one of these common menu paths:
Profile → Security
Account → Security
Settings → Security
Profile picture → Manage account → Security
If you are not already signed in, sign in from the official site or app.
What you should see when this succeeds: a Security or Login & Security page with options such as Password, Sessions, Devices, Two-Factor Authentication, or Recent Activity.
Step 3: Change your password immediately
On the security page, open the password section using one of these common paths:
Security → Password → Change password
Settings → Security → Update password
Account → Login & Security → Password
Enter these literal values into the form:
Current password: your current password
New password: a new password you have never used on any other site
Confirm password: the same new password
If the service offers a checkbox, turn on the literal option:
Sign out of other devices
Sign out everywhere else
Log out other sessions
What you should see when this succeeds: a confirmation message such as "Password changed" or "Your password has been updated," and often a prompt to sign in again.
Step 4: Sign out of all other sessions or devices
If changing the password did not automatically log out other sessions, use the sessions or devices page.
Go to one of these common menu paths:
Security → Sessions
Security → Your devices
Login & Security → Where you're signed in
Settings → Devices
Then click the literal action next to unknown entries, or use the global option:
Sign out all other sessions
Log out of all devices
Revoke all sessions
Remove device
Keep only the device you are using right now if you recognize it.
What you should see when this succeeds: unknown devices disappear from the list, or the page confirms that all other sessions were signed out.
Step 5: Review recent sign-in activity
Open the recent activity page using one of these common paths:
Security → Recent activity
Security → Login history
Account → Security → Recent sign-ins
Look for entries you do not recognize, especially:
New device
New location
Failed sign-in attempts
Approved sign-in from another browser or phone
If the page offers a reporting action, use the literal option:
This wasn't me
Report suspicious activity
Secure account
What you should see when this succeeds: the suspicious event is marked as reported, or the page shows only your expected devices and locations after the password reset.
Step 6: Verify your two-factor sign-in method is still yours
Open the multi-factor authentication section (extra sign-in proof such as an app code, security key, or text message).
Use one of these common menu paths:
Security → Two-Factor Authentication
Security → MFA
Login & Security → Verification methods
Check that the listed methods are yours. Keep only methods you recognize. Remove unknown methods using the literal action:
Remove
Delete
Turn off
Revoke
If you only use text messages today and the service supports an authenticator app, add one now using the literal action:
Add authenticator app
Set up authentication app
Add security key
What you should see when this succeeds: only your phone, authenticator app, or security key is listed as a sign-in method.
Step 7: Check your email account if it uses the same password
If you reused the same password on your email account, change that password too from your email provider's official site.
Use the same pattern:
Profile → Security → Password → Change password
Security → Sessions → Sign out all other sessions
Security → Recent activity
This matters because email access can be used to reset many other accounts.
What you should see when this succeeds: your email account shows a password change confirmation and no unknown active sessions.
Step 8: Save evidence if the requests continue
If you keep getting approval prompts after changing your password, save the details before contacting support or your internal IT team.
Capture these exact items:
Date and time of the prompt
Service name
Screenshot of the prompt
Screenshot of recent sign-in activity
Any unknown device names or locations shown
Store them in a note or email to yourself.
What you should see when this succeeds: you have a clear record of repeated attempts that you can share without guessing.
Verify it works
Use these checks to confirm the account is secure again:
- Try signing in normally from your current device using the new password.
- Return to the security page and confirm these states:
Password changed: shows today's date or a recent timestamp
Sessions/devices: only your current device is active
Recent activity: no new successful sign-ins you do not recognize
Two-factor methods: only your own phone/app/key is listed
- Wait 10-15 minutes. You should not receive any new approval prompts.
- If the service has an account alerts page or sends security emails, confirm you received a legitimate password-change notification from the official domain you normally use.
Expected result: you can sign in with the new password, unknown sessions are gone, and no new unexpected approval requests arrive.
Common pitfalls
Approving the prompt "just to see what happens"
Mistake: tapping Approve, Yes, or entering the code from the unexpected request.
Symptom: a new device appears in your account, or you receive a "new sign-in" email you did not initiate.
Fix: change the password immediately, sign out all other sessions, and review recent activity.
Changing the password from a link in the alert message
Mistake: opening a password-reset page from a text, email, or push notification instead of the official app or site.
Symptom: the page looks slightly wrong, or your new password does not work afterward.
Fix: close the page, open the service directly from your browser or app, and change the password there.
Forgetting to sign out other sessions
Mistake: updating the password but leaving existing sessions active.
Symptom: the attacker stays signed in on another device even though the password changed.
Fix: go to Security → Sessions or Security → Devices and click "Sign out all other sessions" or the equivalent.
Keeping an unknown MFA method on the account
Mistake: leaving an unfamiliar phone number, authenticator app, or security key attached.
Symptom: unexpected approval requests continue, or someone can still complete sign-in challenges.
Fix: open Security → Two-Factor Authentication and remove every method you do not recognize.
Reusing the same password on email or other sites
Mistake: changing only this one account when the same password is used elsewhere.
Symptom: new approval requests return, or password reset emails appear for other services.
Fix: change the reused password everywhere it was used, starting with your email account and any financial or work accounts.
Assuming failed prompts mean nothing happened
Mistake: ignoring repeated denied prompts because you never approved them.
Symptom: approval requests keep arriving, often called MFA fatigue (repeated prompts intended to wear you down).
Fix: change the password, review recent activity, and save screenshots and timestamps if the prompts continue after the reset.
This article was written by an AI system and published pending human review. Verify anything you intend to act on.
Have a project in mind?
Get an instant AI price estimate for it, or talk directly to our team.
One email a month on what we learn building with AI