Microsoft Account Sign-Ins on Mobile IPs
Microsoft runs two sign-in systems that people meet every day: the personal Microsoft account behind Outlook.com, Xbox and OneDrive, and Microsoft Entra ID for work and school accounts. Both record where sign-ins come from and both use that information to decide when to ask for extra verification. If you or your team connect through a SpoofProxies line, knowing how each system reads a US carrier address saves a lot of confusion. This page covers what each one logs, which risk detections a mobile address can touch, and what IT admins should know when a colleague works over a line.
Personal accounts: the recent activity page
A personal Microsoft account keeps a list of recent sign-in activity in its security settings. Each entry shows the time, an approximate location, the address, the platform and browser, and whether the attempt succeeded. Through a carrier line the location will be the metro region the carrier assigns, often a nearby city rather than your own. That is the nature of mobile addresses, which are handed out from regional gateways and shared by many phones through carrier-grade NAT.
If Microsoft thinks a sign-in is unusual, it may send an alert and ask for a code. For an account you own, confirming the sign-in once and then staying on the same metro tends to settle things. Switching between your home broadband and a line in a different state several times a day is what keeps alerts coming.
Work accounts: Entra ID risk detections
For organisations with Entra ID Protection, Microsoft evaluates each sign-in against a set of named risk detections. Several relate to network location. Anonymous IP address flags sign-ins from sources such as Tor or anonymizing VPNs. Atypical travel compares locations of a user's recent sign-ins and flags movement that looks impossible or unusual. Unfamiliar sign-in properties compares the address, ASN, location and client with the user's history. Some detections also use threat intelligence about addresses linked to attacks.
A US carrier line normally is not an anonymizing service, since the address belongs to AT&T, T-Mobile or Verizon. But a user who signs in from an office in Chicago and, an hour later, from a line in Los Angeles can easily trip atypical travel, and a first sign-in from a new carrier ASN can raise unfamiliar properties. Those are the detections doing their job.
Advice for IT admins
If staff legitimately use mobile lines, for example a QA team checking regional content, tell your security team before they start, so detections can be reviewed with context rather than as incidents. Conditional Access can treat known networks as named locations, but carrier addresses rotate within a regional pool, so pinning a single address is fragile. A more workable approach is to keep work sign-ins on the corporate network or a managed device and use the line only in a separate browser profile for the testing itself, never for the admin portal.
If a detection fires on a genuine sign-in, confirming it as safe in the risk reports helps the model learn. Suppressing detections broadly to make a proxy workflow quieter is a poor trade.
What the address does not decide
Neither system hands out access based on the address. Passwords, passkeys, authenticator approvals and device compliance are the gates, and the address feeds risk scoring around them. A calm-looking carrier address will not help anyone into an account they do not own, and we will not support that. Equally, an unusual-looking address will not lock out the owner; it just adds a verification step. For people who use a line for their own personal account, the useful habits are simple: pick one metro, hold a sticky session, keep the device time zone matched to it and sign in from the same browser each time.
If a verification loop keeps repeating, the usual cause is a mix of networks in a short period. Settle on the line or on your usual connection for that account, not both.
Setting up a Microsoft account proxy on SpoofProxies
- Agree with your IT or security team where the line will be used, if it touches a work account.
- Add a line in one metro and keep that metro for the account.
- Create a separate browser profile, set its time zone to the metro and configure the line's credentials.
- Confirm the exit address and carrier before signing in.
- Sign in, complete any verification, and keep the session sticky.
- Review the sign-in activity page afterwards so you recognise the entry later.
Microsoft account proxy questions
Will a mobile line trigger the anonymous IP detection?
It is designed for sources like Tor and anonymizing VPNs, and a carrier address belongs to a mobile network. Other detections, such as atypical travel, are more likely if you switch locations quickly.
Why does my activity page show a different city?
Carrier addresses are assigned from regional gateways, so the location is an estimate for the area rather than your exact position.
Can admins allow a line as a named location?
Carrier addresses rotate within a pool, so a single address is fragile. Keeping the line in a separate testing profile and work sign-ins on managed networks is usually cleaner.
Is using a line for Outlook.com allowed?
Using your own account over a mobile connection is ordinary. Microsoft's terms still govern the account, and a proxy changes only the network path.