Act quickly
First: what can still get you in?
Don't assume you're locked out
Path 1 — Your Windows PC is the way back in
Get in with Windows Hello or a passkey
On the PC, browse to account.microsoft.com. At the sign-in screen, pick Windows Hello (or a passkey) and confirm with your PIN, face or fingerprint. The verification lives on this machine, so the password — whatever the attacker set it to — never comes into it.
Already signed in on the PC? Even simpler: you're in. If neither works, drop down to Path 2.
Sign in
No account? Create one!
Can't access your account?
Microsoft sign-in: enter your email, choose "Use your face, fingerprint, PIN or security key", enter your Windows Hello PIN, then the signed-in account.microsoft.com dashboard
Can't get in on your PC?
Take the password back
With the account open, replace the password:
- Go to Security, then Manage how I sign in
- Under Ways to prove who you are → Enter password, pick Change password
- Hello already vouched for you, so no old password is needed — enter a strong new one twice and Save
The attacker's copy of the old password just became scrap.
Your name
View my benefits
Account
Security
Update your password and sign-in options
Devices
See where you're signed in
account.microsoft.com: Security tab, Manage how I sign in, Ways to prove who you are, Change password, then a New password and Reenter password form with Save
Strip out foreign sign-in methods
Assume the intruder left themselves a spare key under Ways to prove who you are — their own email, number, authenticator or passkey, ready to reset your password next month:
- Read the Ways to prove who you are list entry by entry
- Remove anything you didn't add yourself — no matter how plausible it looks
When only your own methods remain, the propped-open door is shut.
Change password
Change ›
Two-step verification
Manage ›
Ways to prove who you are
Check this list carefully and remove anything you don't recognise.
Ways to prove who you are: an unrecognised attacker-added email method flagged and removed
Throw every session out
A new password doesn't reliably end sessions that are already open — end them yourself:
- Scroll the Security page to Sign out everywhere
- Click it and confirm
Within 24 hours every browser, app and device is signed out where possible — the intruder included, while you simply log back into your own. Give the sign-in activity a quick once-over on your way out.
Additional security
To increase the security of your account, remove your password or require two steps to sign in.
Passwordless account
OFF
Turn on
Two-step verification
ON
Turn off
App passwords
Create a new app password
Sign out everywhere
If you think someone might have unauthorized access to your account, we can protect you by signing you out from your trusted devices. You'll be signed out of browsers, apps and anywhere else your account is used to sign in, where possible, within 24 hours.
Windows Hello lets you sign in to your device apps, online services and networks using your face, fingerprint or a PIN.
Reset Windows Hello on all of my Windows devices
account.live.com security page scrolled to the Sign out everywhere section, then a confirm dialog
Halfway there
Path 2 — Recover through Microsoft
Choose your most familiar device
Where you attempt recovery matters as much as what you type. Use a device and browser this account has seen before, on your usual home network — familiarity carries more weight with Microsoft's checks than almost anything else you control.
Run the reset and prove yourself
Time to prove ownership — use whichever verification route you still hold:
- Open account.live.com/password/reset and enter the account's address
- Verify your identity asks for an authenticator app code first — supply it if you can
- Otherwise pick Use a different verification option, then Email a code or Text a code, confirm the destination and hit Get code
- Type the received code and continue with Next
A saved 25-character recovery code (offered when extra security was switched on) also works via Use a different verification option. Authenticator, passkey or recovery code are the strongest cards — play whichever is still in your hand.
Recover your account
Enter your email, phone, or Skype name to recover your account.
account.live.com password reset: enter your email, choose a verification method, enter the security code, then verified
If you can't pass any of these
This is the last resort, and it doubles as your only support channel. If you keep choosing I don't have any of these on the verification screens — and answer no when asked for your 25-character recovery code — Microsoft eventually drops you onto its account recovery form, shown below.
On the first page you enter the account you've lost, a contact email Microsoft can reply to (use your new inbox) and a captcha. Microsoft emails a code to that contact address to confirm it, then walks you through a few pages of identity questions — your name and birth date, old passwords, which Microsoft products you've used, and the contacts and subject lines of emails you've recently sent. Fill in as much as you can, even rough guesses, and submit it for a real person to review.
Recover your account
What Microsoft account are you trying to get back into?
Email, phone, or Skype name
Note: If you've turned on two-step verification, you can't recover your account this way.
Where should we contact you?
Enter an email address that's different from the one you're trying to recover.
Contact email address
If you don't have another email address, create a new one with Outlook.com
Enter the characters you see
New | Audio
Microsoft's account recovery form (account.live.com/acsr): enter the lost account, a contact email and a captcha, then submit for manual review
Important: two-step verification blocks this form
If you still can't get in
At this point you've genuinely exhausted every way back into the account — a still-signed-in device, every verification option, and the recovery form itself. You can resubmit the form once or twice with more detail (answer from a device and location you've used before), but recovery is never guaranteed, and once you truly can't prove ownership, Microsoft's decision is final. If it doesn't come through, don't get stuck here — the priority now is to limit the damage and rebuild on a fresh, secure inbox, and the next steps walk you through exactly that.
If recovery isn't working
Lock in a fresh password
Verification ends at the new-password screen: 16+ characters, unique to this account, straight into a password manager. Need to change it again later, it lives at Security → Manage how I sign in:
- Open Security, then Manage how I sign in
- Under Ways to prove who you are → Enter password, choose Change password
- Enter it twice, Save
The front door now has a lock the attacker has never seen.
Your name
View my benefits
Account
Security
Update your password and sign-in options
Devices
See where you're signed in
account.microsoft.com Security to Manage how I sign in to Change password: enter and reenter a new password, then Save
Purge sign-in methods that aren't yours
Whoever was inside probably left a way back — their own contact details planted under Ways to prove who you are:
- Open Security → Manage how I sign in and inspect every listed method
- Unfamiliar email, number, authenticator or passkey? Remove it
Only the methods you created should survive this pass.
Change password
Change ›
Two-step verification
Manage ›
Ways to prove who you are
Check this list carefully and remove anything you don't recognise.
Ways to prove who you are list with an unfamiliar method being removed via a confirmation dialog
Force out lingering sessions
The reset alone can leave the attacker's sessions breathing — finish them:
- On Security, scroll to Sign out everywhere
- Confirm it
All sessions on all devices end within 24 hours where possible; yours come back the moment you sign in again. Scan the recent sign-in activity before you leave.
Additional security
To increase the security of your account, remove your password or require two steps to sign in.
Passwordless account
OFF
Turn on
Two-step verification
ON
Turn off
App passwords
Create a new app password
Sign out everywhere
If you think someone might have unauthorized access to your account, we can protect you by signing you out from your trusted devices. You'll be signed out of browsers, apps and anywhere else your account is used to sign in, where possible, within 24 hours.
Windows Hello lets you sign in to your device apps, online services and networks using your face, fingerprint or a PIN.
Reset Windows Hello on all of my Windows devices
Security page Sign out everywhere section with a confirmation dialog; signs out all devices within 24 hours
The reset isn't the finish line
Troubleshooting & FAQs
Which path do I start with?
The hacker changed my password — does a signed-in session still help?
Microsoft won't verify me on the reset page.
They changed my security info. Is the account gone?
How long does the recovery form take?
What to do next
If you got back in ✅
Find out what they touched
Lock it down properly
If you couldn't recover it ⚠️
Why this keeps happening on free email
Rebuild on ground that can't be pulled from under you
Proton Unlimited bundles the encrypted inbox with VPN, Pass and Drive — the complete kit for standing your digital life back up after losing an account.
- End-to-end encrypted
- Swiss-based, no ads
- One plan, every app




- Unhook your Windows PC. Settings → Accounts → switch to a local account (or another Microsoft account) — whoever controls the lost account should not hold a live line into your computer.
- Re-home every login. Anywhere the old address signs in or resets passwords — banking, shopping, gaming, socials — gets a new password and your fresh Proton address as its email and recovery contact.
- Put your contacts on alert. Mail from the old address may not be you; nobody should act on its requests for money, codes or links.
- Watch for misuse. Turn on alerts where possible and keep an eye on services that were tied to the old account.
A different inbox affected?
Was this guide helpful?
Know someone who needs this? Send them the guide.
Written by
Jordan DicksonFounder, CyberSecurityGuides
Founder of CyberSecurityGuides, writing practical, jargon-free guides that help everyday people recover from and protect against online attacks.
Reviewed by CSG Security Engineers
