How to Recover Your Microsoft Account After Being Hacked

    How to get back into a hacked Microsoft account — the sign-in you use for Windows, Xbox, Office and Outlook — and what to do straight after.

    JDCS
    By Jordan Dickson · Reviewed by CSG Security Engineers

    Updated July 2026 · 10 min read

    Your Microsoft account signs you into Windows, Xbox, Office and your inbox — losing it, or finding someone else inside it, touches everything at once. Take a breath: these accounts are usually recoverable, and the fastest route depends on what still lets you in. Work out your situation below, take the account back, then close every door behind the intruder.
    Affiliate disclosure: if you sign up for a paid Proton plan through links on this page, CyberSecurityGuides may earn a commission at no extra cost to you. We only recommend tools we use and trust.

    Act quickly

    Move now rather than perfectly. Every hour inside lets an attacker rework your security info in their favour — start immediately, from a device this account has seen before if you possibly can.

    First: what can still get you in?

    The ace up your sleeve is a Windows PC that's set up with this account: Windows Hello or a passkey lives on the machine itself and can sign you in even after the attacker changes the password. Start with Path 1 if you have one; Path 2 — Microsoft's recovery process — is the fallback.

    Don't assume you're locked out

    Before assuming the worst, look at the PC on your desk. A Windows machine set up with this account is very often still signed in — and if you unlock it with a PIN, face or fingerprint, that's Windows Hello, which can get you back into the account regardless of what the attacker did to the password. Check that route first.

    Path 1 — Your Windows PC is the way back in

    A Windows laptop or desktop set up with this Microsoft account is the strongest recovery tool you own. Unlocking Windows with a PIN, fingerprint or face means Windows Hello is already active — most people have it without ever thinking about it. Hello and passkeys live on the device, not in the password system, so they sign you in even when the attacker holds the password — the one advantage they can't take from a distance.
    1

    Get in with Windows Hello or a passkey

    On the PC, browse to account.microsoft.com. At the sign-in screen, pick Windows Hello (or a passkey) and confirm with your PIN, face or fingerprint. The verification lives on this machine, so the password — whatever the attacker set it to — never comes into it.

    Already signed in on the PC? Even simpler: you're in. If neither works, drop down to Path 2.

    login.microsoftonline.com
    Microsoft

    Sign in

    No account? Create one!

    Can't access your account?

    Next

    Microsoft sign-in: enter your email, choose "Use your face, fingerprint, PIN or security key", enter your Windows Hello PIN, then the signed-in account.microsoft.com dashboard

    Can't get in on your PC?

    No Windows PC set up with this account, Windows Hello isn't an option, or you simply can't sign in here? Don't keep trying — skip straight to Path 2 and recover through Microsoft's account recovery instead. Bear in mind, too, that a more capable attacker may have removed your passkey or Windows Hello from the account to close this route off — if that's happened, Path 2 is your way back.
    Recover through Microsoft (Path 2)
    2

    Take the password back

    With the account open, replace the password:

    1. Go to Security, then Manage how I sign in
    2. Under Ways to prove who you are → Enter password, pick Change password
    3. Hello already vouched for you, so no old password is needed — enter a strong new one twice and Save

    The attacker's copy of the old password just became scrap.

    Microsoft accountY
    Y

    Your name

    View my benefits

    Account
    Your info
    Subscriptions
    Devices
    Security
    Privacy

    Account

    Security

    Update your password and sign-in options

    Devices

    See where you're signed in

    account.microsoft.com: Security tab, Manage how I sign in, Ways to prove who you are, Change password, then a New password and Reenter password form with Save

    3

    Strip out foreign sign-in methods

    Assume the intruder left themselves a spare key under Ways to prove who you are — their own email, number, authenticator or passkey, ready to reset your password next month:

    1. Read the Ways to prove who you are list entry by entry
    2. Remove anything you didn't add yourself — no matter how plausible it looks

    When only your own methods remain, the propped-open door is shut.

    Security

    Change password

    Change ›

    Two-step verification

    Manage ›

    Ways to prove who you are

    Check this list carefully and remove anything you don't recognise.

    Enter passwordUp to date
    Email a codey•••@outlook.com
    Text a code••• ••• ••••
    Email a code attacker@mail.ru Added today — not you?
    View activity
    Remove

    Ways to prove who you are: an unrecognised attacker-added email method flagged and removed

    4

    Throw every session out

    A new password doesn't reliably end sessions that are already open — end them yourself:

    1. Scroll the Security page to Sign out everywhere
    2. Click it and confirm

    Within 24 hours every browser, app and device is signed out where possible — the intruder included, while you simply log back into your own. Give the sign-in activity a quick once-over on your way out.

    Additional security

    To increase the security of your account, remove your password or require two steps to sign in.

    Passwordless account

    OFF

    Turn on

    Two-step verification

    ON

    Turn off

    App passwords

    Create a new app password

    Sign out everywhere

    If you think someone might have unauthorized access to your account, we can protect you by signing you out from your trusted devices. You'll be signed out of browsers, apps and anywhere else your account is used to sign in, where possible, within 24 hours.

    Sign out everywhere

    Windows Hello lets you sign in to your device apps, online services and networks using your face, fingerprint or a PIN.

    Reset Windows Hello on all of my Windows devices

    account.live.com security page scrolled to the Sign out everywhere section, then a confirm dialog

    Halfway there

    The account answers to you again — but what did they leave running? Forwarding, inbox rules, connected apps, app passwords and edited security info all survive this. Sweep for their leftovers before calling it finished.
    Check what they touched

    Path 2 — Recover through Microsoft

    No signed-in device and a changed password leaves Microsoft's account recovery, which decides from many signals whether you're the owner. Familiar hardware, a familiar network and detailed answers all push the decision your way.
    1

    Choose your most familiar device

    Where you attempt recovery matters as much as what you type. Use a device and browser this account has seen before, on your usual home network — familiarity carries more weight with Microsoft's checks than almost anything else you control.

    2

    Run the reset and prove yourself

    Time to prove ownership — use whichever verification route you still hold:

    1. Open account.live.com/password/reset and enter the account's address
    2. Verify your identity asks for an authenticator app code first — supply it if you can
    3. Otherwise pick Use a different verification option, then Email a code or Text a code, confirm the destination and hit Get code
    4. Type the received code and continue with Next

    A saved 25-character recovery code (offered when extra security was switched on) also works via Use a different verification option. Authenticator, passkey or recovery code are the strongest cards — play whichever is still in your hand.

    account.live.com/password/reset
    Microsoft

    Recover your account

    Enter your email, phone, or Skype name to recover your account.

    Next

    account.live.com password reset: enter your email, choose a verification method, enter the security code, then verified

    If you can't pass any of these

    This is the last resort, and it doubles as your only support channel. If you keep choosing I don't have any of these on the verification screens — and answer no when asked for your 25-character recovery code — Microsoft eventually drops you onto its account recovery form, shown below.

    On the first page you enter the account you've lost, a contact email Microsoft can reply to (use your new inbox) and a captcha. Microsoft emails a code to that contact address to confirm it, then walks you through a few pages of identity questions — your name and birth date, old passwords, which Microsoft products you've used, and the contacts and subject lines of emails you've recently sent. Fill in as much as you can, even rough guesses, and submit it for a real person to review.

    account.live.com/acsr
    Microsoft|AccountSign in

    Recover your account

    What Microsoft account are you trying to get back into?

    Email, phone, or Skype name

    Note: If you've turned on two-step verification, you can't recover your account this way.

    Where should we contact you?

    Enter an email address that's different from the one you're trying to recover.

    Contact email address

    If you don't have another email address, create a new one with Outlook.com

    Enter the characters you see

    New | Audio

    RHX WDS4
    Next

    Microsoft's account recovery form (account.live.com/acsr): enter the lost account, a contact email and a captcha, then submit for manual review

    Important: two-step verification blocks this form

    If two-step (two-factor) verification was switched on for the account, this recovery form won't work — Microsoft says so on the form itself.

    If you still can't get in

    At this point you've genuinely exhausted every way back into the account — a still-signed-in device, every verification option, and the recovery form itself. You can resubmit the form once or twice with more detail (answer from a device and location you've used before), but recovery is never guaranteed, and once you truly can't prove ownership, Microsoft's decision is final. If it doesn't come through, don't get stuck here — the priority now is to limit the damage and rebuild on a fresh, secure inbox, and the next steps walk you through exactly that.

    If recovery isn't working

    Tried in earnest and still hitting a wall? Jump to the steps for limiting the damage and rebuilding on a more secure inbox.
    What to do if you can't recover it
    3

    Lock in a fresh password

    Verification ends at the new-password screen: 16+ characters, unique to this account, straight into a password manager. Need to change it again later, it lives at Security → Manage how I sign in:

    1. Open Security, then Manage how I sign in
    2. Under Ways to prove who you are → Enter password, choose Change password
    3. Enter it twice, Save

    The front door now has a lock the attacker has never seen.

    Microsoft accountY
    Y

    Your name

    View my benefits

    Account
    Your info
    Subscriptions
    Devices
    Security
    Privacy

    Account

    Security

    Update your password and sign-in options

    Devices

    See where you're signed in

    account.microsoft.com Security to Manage how I sign in to Change password: enter and reenter a new password, then Save

    4

    Purge sign-in methods that aren't yours

    Whoever was inside probably left a way back — their own contact details planted under Ways to prove who you are:

    1. Open Security → Manage how I sign in and inspect every listed method
    2. Unfamiliar email, number, authenticator or passkey? Remove it

    Only the methods you created should survive this pass.

    Security

    Change password

    Change ›

    Two-step verification

    Manage ›

    Ways to prove who you are

    Check this list carefully and remove anything you don't recognise.

    Enter passwordUp to date
    Email a codey•••@outlook.com
    Text a code••• ••• ••••
    Email a code attacker@mail.ru Added today — not you?
    View activity
    Remove

    Ways to prove who you are list with an unfamiliar method being removed via a confirmation dialog

    5

    Force out lingering sessions

    The reset alone can leave the attacker's sessions breathing — finish them:

    1. On Security, scroll to Sign out everywhere
    2. Confirm it

    All sessions on all devices end within 24 hours where possible; yours come back the moment you sign in again. Scan the recent sign-in activity before you leave.

    Additional security

    To increase the security of your account, remove your password or require two steps to sign in.

    Passwordless account

    OFF

    Turn on

    Two-step verification

    ON

    Turn off

    App passwords

    Create a new app password

    Sign out everywhere

    If you think someone might have unauthorized access to your account, we can protect you by signing you out from your trusted devices. You'll be signed out of browsers, apps and anywhere else your account is used to sign in, where possible, within 24 hours.

    Sign out everywhere

    Windows Hello lets you sign in to your device apps, online services and networks using your face, fingerprint or a PIN.

    Reset Windows Hello on all of my Windows devices

    Security page Sign out everywhere section with a confirmation dialog; signs out all devices within 24 hours

    The reset isn't the finish line

    Back in — good. Now find what was changed while you were locked out: rules, forwarding, connected apps and app passwords keep working straight through a recovery. A few minutes of checking closes them all.
    Check what they touched

    Troubleshooting & FAQs

    Which path do I start with?
    A Windows PC set up with the account — or any session where you're still signed in with a known password — means Path 1. Locked out with a changed password and no Hello-equipped machine? Path 2 recovers through Microsoft.
    The hacker changed my password — does a signed-in session still help?
    Yes, if the device has Windows Hello or a passkey: those verify you locally, so Microsoft lets you set a new password without knowing the old one (Path 1). Without them, go to account.live.com/password/reset — a familiar signed-in device still strengthens your verification there.
    Microsoft won't verify me on the reset page.
    Retry from the device, browser and network the account knows best, and give every detail you can rather than skipping questions. If that fails, the account recovery form is next — and resubmitting after a day or two genuinely changes outcomes, since Microsoft weighs many signals.
    They changed my security info. Is the account gone?
    Not necessarily. The account recovery form accepts other proof of ownership — previous passwords, subject lines you've sent, contacts you email often. Be thorough and honest; if Microsoft's checks still can't be met, though, there's no appeal that overrides them.
    How long does the recovery form take?
    Microsoft usually emails its decision within 24 hours to the contact address you supply. A rejection isn't final — resubmit with more detail and the odds improve.

    What to do next

    If you got back in ✅

    Password reset, sessions ended — the remaining work is confirming nothing they planted is still ticking, and hardening the account against round two.

    Find out what they touched

    Ten checks that surface an intruder's leftovers — sign-in methods, aliases, app passwords, rules and more — so each one gets removed.
    See the signs of compromise

    Lock it down properly

    Two-step verification, security info that's exclusively yours, and a password used nowhere else — the full hardening pass for the account behind your PC.
    Secure your Microsoft account

    If you couldn't recover it ⚠️

    If Microsoft's checks genuinely can't be satisfied, plan for the account being gone — possibly still under the attacker's control. Priority one is standing up a fresh, secure inbox, because every account you move off the lost address needs somewhere trustworthy to land.
    Then rebuild where this failure mode doesn't exist. You've just felt the weakness of a big-tech account: an enormous target, with recovery that turns into a black box the moment an attacker owns your security info. Proton Mail is engineered the other way round — end-to-end encrypted, Swiss-jurisdiction privacy law, keys held by you, recovery through channels you control, and no ad machinery reading a word. An inbox that can't be quietly reset out from under its owner.

    Why this keeps happening on free email

    Why an encrypted, privacy-first inbox is structurally harder to take over — and what moving actually involves.
    Why switch to Proton Mail
    Proton Unlimited

    Rebuild on ground that can't be pulled from under you

    Proton Unlimited bundles the encrypted inbox with VPN, Pass and Drive — the complete kit for standing your digital life back up after losing an account.

    • End-to-end encrypted
    • Swiss-based, no ads
    • One plan, every app
    New inbox running? Then sever the lost account and contain what it can reach:
    • Unhook your Windows PC. Settings → Accounts → switch to a local account (or another Microsoft account) — whoever controls the lost account should not hold a live line into your computer.
    • Re-home every login. Anywhere the old address signs in or resets passwords — banking, shopping, gaming, socials — gets a new password and your fresh Proton address as its email and recovery contact.
    • Put your contacts on alert. Mail from the old address may not be you; nobody should act on its requests for money, codes or links.
    • Watch for misuse. Turn on alerts where possible and keep an eye on services that were tied to the old account.

    A different inbox affected?

    Locked out of a different provider's inbox? The same access-first approach works everywhere — here's the universal version.
    Recover any email account

    Was this guide helpful?

    Know someone who needs this? Send them the guide.

    JD

    Written by

    Jordan Dickson

    Founder, CyberSecurityGuides

    Founder of CyberSecurityGuides, writing practical, jargon-free guides that help everyday people recover from and protect against online attacks.

    Reviewed by CSG Security Engineers

    More from Device Security