The Problem
A Microsoft account is not just an email login. It is the key to your Windows sign-in, your OneDrive files, your Xbox library and payment method, your Office subscription, and — critically — your BitLocker recovery key. Losing control of it is one of the highest-impact account compromises there is.
Attackers who get in typically do three things fast: change the recovery email and phone so you cannot get back, add their own authentication method, and either drain the payment method or hold the account for resale. The sooner you start recovery, the better the outcome.
If you can still sign in, you are in a much stronger position. Do Step 1 immediately and do not wait.
The PC was remotely accessed by a "support agent"? Do what to do after a remote access scam alongside this.
The Fix: Step-by-Step
Step 1: If You Can Still Sign In, Lock It Down Now
Go to account.microsoft.com from a device you trust and, in this order:
- Security → Change my password. Use a long, unique password from your password manager.
- Security → Advanced security options → Sign me out — this terminates every active session everywhere.
- Review Ways to prove who you are. Delete any email address, phone number, or authenticator you do not recognise.
- Turn on Two-step verification if it is off, using the Microsoft Authenticator app rather than SMS.
- Save the recovery code shown, offline.
Do not skip the sign-out. Changing the password alone can leave an attacker's existing session live.
Step 2: If You Cannot Sign In, Try Password Reset First
Go to account.live.com/password/reset. If your recovery email or phone is still yours, you will get a code and be back in within minutes. Then do Step 1 immediately.
If the recovery options shown belong to the attacker — an unfamiliar masked address or phone — stop and go to Step 3. Do not keep retrying; repeated failures do not help and can lock the account further.
Step 3: Use the Account Recovery Form Properly
When automated reset is impossible, account.live.com/acsr is the manual review route. It is judged on how much you can prove, so preparation matters.
Before you start, gather:
- Old passwords you have used on the account — even from years ago.
- Subject lines of recent emails you sent, and addresses you email often.
- The date the account was created, roughly.
- Skype names, Xbox gamertags, and any linked service names.
- The last four digits and type of any card on file.
- Names of folders in your OneDrive.
Then:
- Submit the form from a device and network you have used with the account before — a familiar IP address and browser materially improve your odds.
- Give an alternate contact email you control for the response.
- Answer everything you can. Blanks are what usually cause rejection.
- Wait up to 24 hours for the emailed decision.
If it is rejected, you can submit again with more detail. Each attempt should add information rather than repeat the last one.
Step 4: Check What Happened While They Were In
Once you are back in, at account.microsoft.com → Security → Sign-in activity, review every entry. Note unfamiliar locations, devices, and app types — and whether any show as "successful".
Then check:
- Privacy → Recent activity for changes to your profile.
- Devices — remove any device you do not own. Note that removing a device also removes its BitLocker recovery keys from the account, so check Step 6 first.
- Payment options — remove unfamiliar cards, and check Order history and Subscriptions for purchases you did not make.
- Family — remove any account added to your family group.
Step 5: Clean Out the Mailbox Rules
If your account uses Outlook.com, check for the classic persistence tricks. In Outlook on the web: Settings → Mail → Forwarding, and Settings → Mail → Rules.
Remove any forwarding address you did not add, and any rule that deletes, moves, or forwards messages — especially rules keyed on words like "security", "password", "bank", or "Microsoft". These exist so you never see the alerts.
Also check Sync email for connected accounts you did not add, and Aliases under Your info for an alias added to receive resets.
Step 6: Recover Your BitLocker Key Before Removing Devices
This is the step that catches people out. If your Windows PC has BitLocker enabled — which is default on many Windows 11 machines — the recovery key is stored in this account, and removing the device from the account removes the key with it.
Go to account.microsoft.com/devices/recoverykey, and save every key shown somewhere offline before you touch the device list. If you have already lost access to the key and the PC asks for it, see BitLocker recovery key loop.
Step 7: Check the PC Itself
An account compromise and a compromised PC often travel together — infostealer malware on the machine is one of the most common ways the credentials were taken in the first place.
Run a Full scan then a Microsoft Defender Offline scan: remove virus and malware. Then check for persistence with remove malicious scheduled tasks and startup persistence, and review browser extensions with remove malicious browser extensions.
If you skip this, whatever took your password takes the new one too.
Step 8: Fix Windows Sign-In on Your PC
After a password change, the PC may keep asking for the old one, or refuse the new one until it can reach Microsoft.
Sign in with your Windows Hello PIN, which is device-local and unaffected, then connect to the internet so the account state syncs. If sign-in problems persist, see Microsoft account sign-in problems.
Step 9: Harden It So It Does Not Repeat
- Add a passkey: Advanced security options → Add a new way to sign in — see set up passkeys.
- Turn on passwordless account once you have two passkeys and a recovery code saved.
- Set recovery email and phone to addresses you actually monitor: set up account recovery options.
- Check whether the old password is in circulation: check if your email was in a data breach.
- Never reuse this password anywhere. It is the master key to your PC.
What Not to Do
- Do not create a new Microsoft account and abandon the old one before recovering it. You would lose OneDrive files, Office and Xbox licences, and any BitLocker keys — and the attacker keeps a working account with your name on it.
- Do not pay anyone offering account recovery. Microsoft's form is the only route; paid "recovery specialists" cannot do anything you cannot.
- Do not remove devices from the account before saving BitLocker keys.
- Do not use the same recovery email you use as a login for another compromised service.
FAQ
How long does Microsoft account recovery take?
The automated reset is immediate if your recovery email or phone still works. The manual recovery form is typically answered within 24 hours. Repeated submissions do not speed it up — a more complete submission does.
The recovery form keeps rejecting me. What else can I try?
Submit again from a device, browser, and network you have previously used with the account, and add more verifiable detail: older passwords, exact email subject lines you sent, folder names in OneDrive, card last-four digits, and linked Xbox or Skype identifiers. Partial answers to many questions beat perfect answers to a few.
Will I lose my OneDrive files?
Not if you recover the account. Files stay in place while it is locked. If the attacker deleted them, OneDrive keeps deleted items in the Recycle Bin for 30 days and supports Files Restore to roll the whole drive back to a point in time — use it as soon as you are back in.
Can I still use my Windows PC while locked out?
Usually yes — your Windows Hello PIN is local to the device and keeps working. What breaks is Store, OneDrive sync, and settings sync. Do not remove the account from Windows while locked out; that can make things considerably harder.
They changed my recovery phone and email. Is the account gone?
No. That is precisely what the manual recovery form exists for. It is judged on knowledge only the real owner would have, not on the current recovery settings.
Should I turn on two-step verification even though it is inconvenient?
Yes — it is the single change that most reliably prevents this happening again. Use the Microsoft Authenticator app rather than SMS, since SMS can be intercepted through a SIM swap.
Still Not Working?
If recovery is repeatedly refused, contact Microsoft support through support.microsoft.com from a working account and explain the account is compromised rather than merely forgotten — that routes it differently. If money was taken, report it to your bank and to your national fraud reporting service in parallel.
Related: recover a hacked email account, review and revoke app access and active sessions, set up two-factor authentication.
Related guides
How to Set Up Passkeys for Passwordless Sign-In
Passkeys cannot be phished, reused, or stolen in a breach. Set them up on Windows 11, your phone, and your main accounts — and keep a way back in if a device is lost.
How to Check If Your Email Was in a Data Breach
Find out which breaches exposed your email and passwords, work out what is actually at risk, and fix it in the right order — without falling for a fake breach alert.
Enable LSA Protection and Credential Guard in Windows 11
Stop password-stealing tools reading saved credentials out of memory. Turn on LSA protection on any Windows 11 PC, and Credential Guard on Pro and Enterprise.
Enable Smart App Control and SmartScreen in Windows 11
Smart App Control blocks untrusted apps before they run, and SmartScreen warns on risky downloads. Set both up, and understand why Smart App Control needs a clean install.
How to Prevent a SIM Swap Attack on Your Phone Number
If someone ports your number, every SMS code goes to them. Lock your mobile account with a port-out PIN, move 2FA off SMS, and know what to do in the first hour.