How to Tell If Your Microsoft Account Has Been Compromised

    Quick checks to confirm whether someone else has been inside the Microsoft account behind your PC, Xbox and inbox — and how to close every foothold.

    JDCS
    By Jordan Dickson · Reviewed by CSG Security Engineers

    Updated July 2026 · 7 min read

    One account sits behind your Windows PC, your Xbox, your Office apps and your Outlook inbox — so a strange sign-in warning from Microsoft, or just a nagging feeling that something's off, deserves a proper answer. The checks below settle it. They confirm whether anyone else has genuinely been inside your Microsoft account, and they dig out the quiet footholds an intruder relies on to come back — forwarding and inbox rules, spare aliases, app passwords, connected apps and doctored security info — so every one can be closed behind them.
    Affiliate disclosure: if you create or upgrade a paid Proton plan through links on this page, CyberSecurityGuides may earn a commission at no extra cost to you. We only recommend tools we use and trust.

    Ten checks for unauthorised access

    1

    Start with the device list

    From a device you trust, sign in at account.microsoft.com and open the Devices tab. Every machine holding your account shows up here — including an attacker's own computer, if they signed in from one. Hunt for any Windows PC or laptop that isn't yours, particularly anything added recently or oddly located. Open its details (Info & support or See details), satisfy yourself it's foreign, and cut it loose with Remove this device.

    Telling yours apart

    Your own device is usually marked This device — leave that one. Treat any unfamiliar machine, particularly a Windows PC added today or signed in from a place you’ve never been, as the one to remove.
    Microsoft

    Sign in

    yourname@outlook.com

    Password

    Forgot password?

    Sign in

    account.microsoft.com Devices tab listing signed-in devices, with an unfamiliar Windows PC flagged and removed

    What this list doesn't show

    This tab only covers Microsoft devices — Windows PCs, Xbox consoles and the like that are linked to your account. It does not show every place your account is signed in: someone reading your mail through Outlook on the web in a browser won’t appear here at all. So a normal-looking Devices list isn’t proof you’re alone — your sign-in activity (the next step) is what catches browser sessions, and a full Sign out everywhere ends them.
    2

    Read the sign-in activity

    Move to the Security tab and pick View my sign-in activity under Account Security. Each entry shows when, roughly where, on what device, and whether it got in. A wall of unsuccessful attempts from random countries is background noise — brute-force bots hammer every Microsoft account on earth — so don't let the failures rattle you. The line that matters is a successful sign-in you can't claim: open it, choose This wasn't me, and Microsoft walks you straight into a password change and lockdown.

    Reading the activity list

    A sign-in from a city near you can still be legitimate — location is estimated from the IP address and is often imprecise. The clearest red flags are devices you don’t own, sign-ins at times you were asleep or offline, or a successful sign-in somewhere you’ve never been. And if you use a VPN or relay service, your own legitimate sign-ins can show up at unfamiliar or distant locations.

    Bear in mind, too, that this list usually only covers the last 30 days. Anything an attacker did before that won’t appear here — so a clean list is not a guarantee nothing happened. That’s exactly why the rest of these checks still matter.
    Microsoft accountY
    Y

    Your name

    View my benefits

    Account
    Your info
    Subscriptions
    Devices
    Security
    Privacy

    Devices

    SURFACE-LAPTOP

    Surface Laptop 5

    DESKTOP-K7E5AAP

    Z790 Gaming PC

    Devices checked. Next, head to Security to review your sign-in activity.

    account.microsoft.com Security page, View my sign-in activity, then Recent activity showing an unrecognised successful sign-in from another country

    Securing the basics isn't the whole job

    Choosing This wasn’t me is the right first move — Microsoft helps you change your password and sign the intruder’s sessions out, which is enough to lock them out right now. But that only covers the basics. Someone who’s had access may have left quieter ways back in — forwarding rules, hidden inbox rules, extra aliases, connected apps or added recovery methods — that a password change alone won’t touch. Work through the rest of this guide to find and close them, so the account stays yours.
    3

    Audit your security info

    Back on Security, open Manage how I sign in and study every entry under Ways to prove who you are. This list is the master key rack: each email, phone number, authenticator and passkey on it can reset your password or wave through two-step verification.

    An intruder's favourite parting gift is adding one of their own. Remove every method you didn't personally set up — what remains should be yours alone.

    Microsoft accountY
    Y

    Your name

    View my benefits

    Account
    Your info
    Subscriptions
    Devices
    Security
    Privacy

    Security

    How you sign in, the devices you're signed into, and your account's online security.

    Account Security

    Sign in and recovery settings.

    Manage how I sign in
    View my sign-in activity

    File backup and security

    Ways to prove who you are list with an attacker-added recovery email flagged and removed

    Can't remove it? Add a safe method first

    Microsoft won’t let you delete your last remaining ways to sign in — so if you only have a couple of basic methods set up, it may refuse to remove the attacker’s until you’ve added another. If that happens, add an alternative email address you control first, then come back and remove the rogue one. Don’t have a separate, secure address to use? A Proton Mail account is a great choice — it’s end-to-end encrypted and Swiss-based, giving you a clean recovery address the attacker has never had access to.

    Set up a secure Proton Mail address

    End-to-end encrypted and based in Switzerland — a clean inbox the attacker has never touched, ideal as a safe recovery address you fully control.

    Get Proton Mail
    4

    Clear out app passwords

    Scroll the same page to App passwords. These let a mail client or app log straight into the mailbox, and they survive password changes and security tightening — a purpose-built backdoor if an attacker created one. Microsoft only surfaces the Remove existing app passwords link when at least one exists, so the link's mere presence is a warning if you never made any. They can't be inspected individually — wipe the lot, then recreate any you genuinely use.
    Microsoft accountYour infoPrivacySecuritySubscriptionsDevices

    Additional security

    App passwords

    Some apps and devices (such as Xbox 360, Windows Phone, or mail apps on your other devices) don't support security codes for two-step verification. In these cases, you need to create an app password to sign in. Learn more about app passwords

    Create a new app password

    Remove existing app passwords

    Manage how I sign in page, App passwords section, removing all existing app passwords

    Why remove them all

    Because the Remove existing app passwords link only appears when an app password is present — and you can’t see which ones exist or when they were created — there’s no way to single out a rogue one. If you use a desktop or phone mail program like Apple Mail or Outlook desktop, you may well have set one up yourself, so it isn’t always sinister — but since you can’t tell them apart, it’s safer to remove them all and set up fresh ones. Any legitimate app will simply prompt you to sign in again.
    5

    Cycle the recovery code

    At the bottom of the page, find the Recovery code section and hit Generate a new code. That 25-character code can resurrect access to the whole account, and generating a replacement kills the old one on the spot — a copy sitting in an attacker's notes becomes worthless. Store the new one somewhere safe; Microsoft shows it exactly once.
    Microsoft accountYour infoPrivacySecuritySubscriptionsDevices

    Additional security

    Passwordless account

    OFF

    Turn on

    Two-step verification

    OFF

    Turn on

    Sign out everywhere

    Sign out everywhere

    Recovery code

    You can use this code to access your account if you lose access to your sign-in info. Print this out and keep it in a safe place or take a picture of it.

    Generate a new code

    Microsoft account Security page scrolled to Additional security, replacing the recovery code so a new one is generated and the old one is invalidated

    Why replace it even if nothing looks wrong

    Generating a recovery code does show up in your recent activity — but remember that log only goes back 30 days. If an attacker generated one before that window you won’t see it, and Microsoft never displays your current code, so there’s no way to tell whether it’s still the one you set. The safe move is to replace it regardless: a fresh code cancels any old one an attacker might be holding, even one you can’t see.
    6

    Hunt for planted aliases

    A Microsoft-only trap that's easy to miss. An alias is an additional address that signs into — and sends from — the same account, which makes it a discreet spare key an intruder can keep long after you've reset everything else.

    Open the Your info tab, find Account info and choose Edit account info to reach Manage how you sign in to your account. Every address on the account appears under Account usernamedelete any you didn't create.

    About the primary alias

    You can’t remove the primary alias. If an unfamiliar address has been set as primary, switch your real one back to primary first, then remove the rogue one.
    Microsoft accountY
    Y

    Your name

    View my benefits

    Account
    Your info
    Subscriptions
    Devices
    Security
    Privacy

    Your info

    Account info

    Edit account info
    Email addressyourname@outlook.com
    Phone numberNone
    Sign-in preferencesLink your phone to your PCClose account

    account.live.com names Manage page showing account aliases, with an unrecognised alias being removed

    7

    Vet connected apps

    Open the Privacy tab and choose App access for the roster of third-party apps that can reach your data. Hit Details on anything unfamiliar — an app that can read mail or contacts, or that keeps access while you're away, gets Stop sharing unless you set it up yourself. App access rides on its own tokens and shrugs off password changes, which is precisely why attackers lean on it.

    Check the permissions, not the name

    Don’t judge by the name alone — a harmless-looking app can hold full mailbox access. Open it and read exactly what it can do before you decide.
    Microsoft accountY
    Y

    Your name

    View my benefits

    Account
    Your info
    Subscriptions
    Devices
    Security
    Privacy

    Privacy

    Manage your privacy settings and review the data apps can access for your Microsoft account.

    Empower your productivity

    Location

    Directions and info from my location data

    No data

    Browsing and search

    Suggestions from my browsing history

    No data

    Apps and services

    Improve products using my activity data

    Activities: 7

    App access

    Choose which apps and services can access my info

    Apps: 1

    People suggestions

    Expand suggestions from my contacts

    account.microsoft.com consent page, opening a suspicious app with full mailbox access and removing its permissions

    8

    Inspect mail forwarding

    Now into the inbox itself: outlook.live.com, the Settings gear, then Mail → Forwarding and IMAP. Forwarding switched on to a stranger's address means a duplicate of everything you receive — password resets included — flows out silently, no matter how many times you change the password. Unrecognised destination? Clear the address, flip Enable forwarding off, and Save.

    Use a computer

    These settings aren’t in the mobile app. Open Outlook in your phone’s browser and request the desktop site if you’re away from a computer.
    Outlook
    Search
    Y
    New mail DeleteArchiveReportMove toReply allRead / Unread

    Favourites

    Inbox16
    Drafts
    Archive

    yourname@outlook.com

    Inbox16
    Junk Email
    Drafts
    Sent Items
    Deleted
    Archive
    FocusedOther

    Microsoft account team

    11:44

    Your single-use code

    Hi yourname@outlook.com, we received your request…

    May

    Coles at Flybuys

    12/05

    It's time to redeem your credits

    Everyday Rewards

    12/05

    Remember, Everyday Travel

    Expedia.com.au

    12/05

    Save 15%+ on winter escapes

    David Jones

    12/05

    25% Off Winter Fashion

    Harris Scarfe

    12/05

    Winter Sale is On Now!

    Your single-use code

    MT

    Microsoft account team

    account-security-noreply@accountprotection.microsoft.com

    Hi yourname@outlook.com,

    We received your request for a single-use code to use with your Microsoft account.

    Your single-use code is: 234615

    Outlook Settings, Mail, Forwarding pane showing forwarding switched on to an unknown address, then turned off and saved

    9

    Go through the inbox rules

    Stay in Settings → Mail and open Rules. A planted rule can shunt or destroy security alerts before you ever see them, or quietly copy sensitive threads somewhere else. Remove every rule you didn't build — and treat anything touching codes, passwords or security mail as hostile.

    Spotting a hidden rule

    Rogue rules are often given a blank or single-character name (like “.”) to make them easy to overlook, so read the conditions, not just the name. And watch for any rule that forwards or redirects your mail to another address — that’s a second, separate way to siphon your email, independent of the Forwarding setting you turned off in the last step. A clean forwarding screen doesn’t rule it out, so a rule like this needs deleting too.
    Outlook
    Search
    Y

    Settings

    Search
    Account
    General
    Email
    Calendar
    People
    Layout
    Compose
    Smart suggestions
    Attachments
    Rules
    Conditional formatting
    Sweep
    Junk email
    Customise actions
    Message handling
    Forwarding and IMAP
    Subscriptions

    Forwarding and IMAP

    Forwarding

    You can forward your email to another account.

    Forwarding is off. Next, open Rules from the list on the left.

    Outlook Settings, Mail, Rules pane revealing a hidden rule that deletes security messages, then deleting it

    10

    Sign out everywhere, reset Windows Hello

    Finish back at account.microsoft.com: open Security → Manage how I sign in and scroll to Sign out everywhere. One click ends every session on every browser, app and device within 24 hours — the attacker's included; you simply sign back in on your own machines. Then take the option directly beneath it, Reset Windows Hello on all of my Windows devices — it strips any face, fingerprint or PIN sign-in an intruder may have enrolled on hardware you've never seen, without locking you out of your own.
    Microsoft accountY
    Y

    Your name

    View my benefits

    Account
    Your info
    Subscriptions
    Devices
    Security
    Privacy

    Welcome, Your name

    yourname@outlook.com

    Security

    Update your password and sign-in options

    Devices

    See where you're signed in

    Back at account.microsoft.com, the Security page Sign out everywhere section, confirming to sign out of all browsers, apps and devices within 24 hours

    A clean finish

    If you haven’t already changed your account password, do that too — otherwise a signed-out attacker could simply log straight back in with the old one. The full password-and-two-step lockdown is covered in the secure your account guide linked below. Signing out everywhere can take up to 24 hours to take full effect and can’t sign you out of Xbox, but it’s the cleanest way to end any session you didn’t catch in the earlier checks.

    Frequently asked questions

    Could someone be reading my mail without any obvious sign?
    Comfortably. Forwarding rules, inbox rules, connected apps and app passwords all operate in silence — and several keep working straight through a password change. That's why this checklist goes well beyond sign-ins.
    Microsoft alerted me about a sign-in that was actually mine.
    Then the alert did its job — your own new device, browser or holiday triggers identical warnings. Only an unfamiliar device, place or hour deserves action.
    Will a password change kick everyone else out?
    Not reliably on its own. Use Sign out everywhere on the Security page — every other session dies within 24 hours — then add two-step verification so the next stolen password is useless.
    What if I can't sign in at all?
    Start recovery immediately; every hour of delay helps the attacker. Our Microsoft account recovery guide takes you through it even when the password and security info have already been changed.

    What to do next

    If you found something

    Intruder out, footholds cleared — now bolt the door. Harden the account with two-step verification and security info that's exclusively yours.
    Secure your Microsoft account

    If everything looks clean

    A clean sweep — so use the moment. The inbox behind a Microsoft account is a permanent target, and it's the springboard for everything else you own. An end-to-end encrypted mailbox like Proton Mail means nobody but you can read a word of it — a structural upgrade, not a tweak.
    Why switch to Proton Mail

    Worried about another account?

    These tricks aren't unique to Microsoft — any inbox can hide the same traps. The universal checklist covers every provider.
    Signs any email is hacked

    Was this guide helpful?

    Know someone who needs this? Send them the guide.

    JD

    Written by

    Jordan Dickson

    Founder, CyberSecurityGuides

    Founder of CyberSecurityGuides, writing practical, jargon-free guides that help everyday people recover from and protect against online attacks.

    Reviewed by CSG Security Engineers

    More from Device Security