Act quickly
Start here: where can you still get in?
Don't assume you're locked out
Path 1 — Recover from your Windows PC (your best hope)
Sign in with Windows Hello or a passkey
Open a browser on your PC and go straight to account.microsoft.com. When it asks you to sign in, choose Windows Hello (or a passkey) and verify with your PIN, face or fingerprint. Because Hello is tied to this device, it signs you in without the password — even if the attacker changed it.
If your PC's already signed in, even better — you're in. If you can't get in on the PC at all, use Path 2.
Sign in
No account? Create one!
Can't access your account?
Microsoft sign-in: enter your email, choose "Use your face, fingerprint, PIN or security key", enter your Windows Hello PIN, then the signed-in account.microsoft.com dashboard
Can't get in on your PC?
Change your password
You're already in your account — now reset your password:
- Open the Security tab, then Manage how I sign in
- Under Ways to prove who you are → Enter password, choose Change password
- Because Windows Hello already verified you, it won't ask for your old password — just enter a strong new one, reenter it, and Save
Changing it stops the attacker signing in with the old password.
Your name
View my benefits
Account
Security
Update your password and sign-in options
Devices
See where you're signed in
account.microsoft.com: Security tab, Manage how I sign in, Ways to prove who you are, Change password, then a New password and Reenter password form with Save
Remove any sign-in methods you don't recognise
While they were in, the attacker may have quietly added their own email, phone or app under Ways to prove who you are — a backdoor to reset your password all over again later. Clear it out:
- On the Ways to prove who you are list, read every entry carefully
- For anything you don't recognise — an unfamiliar email, phone number, authenticator or passkey — choose Remove
Leave only the methods you set up yourself. This shuts the door the attacker propped open.
Change password
Change ›
Two-step verification
Manage ›
Ways to prove who you are
Check this list carefully and remove anything you don't recognise.
Ways to prove who you are: an unrecognised attacker-added email method flagged and removed
Sign out everywhere
Changing your password doesn't always end the attacker's existing sessions, so force everyone out:
- On the Security page, scroll down to the Sign out everywhere section
- Click Sign out everywhere and confirm
This signs you out of every browser, app and device your account is used on, where possible, within 24 hours — you'll just sign back in on yours. While you're there, glance over your recent sign-in activity for anything unfamiliar.
Additional security
To increase the security of your account, remove your password or require two steps to sign in.
Passwordless account
OFF
Turn on
Two-step verification
ON
Turn off
App passwords
Create a new app password
Sign out everywhere
If you think someone might have unauthorized access to your account, we can protect you by signing you out from your trusted devices. You'll be signed out of browsers, apps and anywhere else your account is used to sign in, where possible, within 24 hours.
Windows Hello lets you sign in to your device apps, online services and networks using your face, fingerprint or a PIN.
Reset Windows Hello on all of my Windows devices
account.live.com security page scrolled to the Sign out everywhere section, then a confirm dialog
You're not out of the woods yet
Path 2 — Recover through Microsoft
Start on a device you've used before
Before you go near the recovery page, pick up a device and browser you've signed in with before — ideally on your home network. Microsoft trusts familiar devices, browsers and networks far more, and that can be the single biggest factor in getting back in.
Recover your account and verify it's you
Now recover the account and prove it's you. Microsoft will offer whatever verification options are on the account — try any of them you can still access:
- Go to account.live.com/password/reset and enter your Outlook, Hotmail or Live address
- On Verify your identity, Microsoft asks for a code from your authenticator app first — if you have it, enter it and continue
- If not, choose Use a different verification option, then pick Email a code or Text a code, confirm the address or number and select Get code
- Enter the code Microsoft sends you and select Next
If you ever generated and saved your 25-character recovery code (Microsoft offers one when you turn on extra security), that's another way in — choose Use a different verification option and enter it. An authenticator app, passkey or recovery code is the fastest and strongest; use whichever you still control.
Recover your account
Enter your email, phone, or Skype name to recover your account.
account.live.com password reset: enter your email, choose a verification method, enter the security code, then verified
If you can't pass any of these
This is the last resort, and it doubles as your only support channel. If you keep choosing I don't have any of these on the verification screens — and answer no when asked for your 25-character recovery code — Microsoft eventually drops you onto its account recovery form, shown below.
On the first page you enter the account you've lost, a contact email Microsoft can reply to (use your new inbox) and a captcha. Microsoft emails a code to that contact address to confirm it, then walks you through a few pages of identity questions — your name and birth date, old passwords, which Microsoft products you've used, and the contacts and subject lines of emails you've recently sent. Fill in as much as you can, even rough guesses, and submit it for a real person to review.
Recover your account
What Microsoft account are you trying to get back into?
Email, phone, or Skype name
Note: If you've turned on two-step verification, you can't recover your account this way.
Where should we contact you?
Enter an email address that's different from the one you're trying to recover.
Contact email address
If you don't have another email address, create a new one with Outlook.com
Enter the characters you see
New | Audio
Microsoft's account recovery form (account.live.com/acsr): enter the lost account, a contact email and a captcha, then submit for manual review
Important: two-step verification blocks this form
If you still can't get in
At this point you've genuinely exhausted every way back into the account — a still-signed-in device, every verification option, and the recovery form itself. You can resubmit the form once or twice with more detail (answer from a device and location you've used before), but recovery is never guaranteed, and once you truly can't prove ownership, Microsoft's decision is final. If it doesn't come through, don't get stuck here — the priority now is to limit the damage and rebuild on a fresh, secure inbox, and the next steps walk you through exactly that.
If recovery isn't working
Set a strong new password
Recovery ends by having you set a new password — make it long (16+ characters), unique to this account, and saved in a password manager. To change it again at any time, go to Security → Manage how I sign in (shown below):
- Open the Security tab, then Manage how I sign in
- Under Ways to prove who you are → Enter password, choose Change password
- Enter your new password, reenter it, and Save
A fresh password the attacker doesn't know locks them out of the front door.
Your name
View my benefits
Account
Security
Update your password and sign-in options
Devices
See where you're signed in
account.microsoft.com Security to Manage how I sign in to Change password: enter and reenter a new password, then Save
Remove any sign-in methods you don't recognise
While they had access, the attacker may have quietly added their own email, phone or app under Ways to prove who you are — a backdoor to reset your password all over again later. Clear it out:
- Open Security → Manage how I sign in and read every entry under Ways to prove who you are
- For anything you don't recognise — an unfamiliar email, phone number, authenticator or passkey — choose Remove
Leave only the methods you set up yourself. This shuts the door the attacker propped open.
Change password
Change ›
Two-step verification
Manage ›
Ways to prove who you are
Check this list carefully and remove anything you don't recognise.
Ways to prove who you are list with an unfamiliar method being removed via a confirmation dialog
Sign out everywhere
Resetting your password doesn't always end the attacker's existing sessions, so force everyone out:
- On the Security page, scroll down to the Sign out everywhere section
- Click Sign out everywhere and confirm
This signs you out of every browser, app and device the account is used on, where possible, within 24 hours — you'll just sign back in on yours. While you're there, glance over your recent sign-in activity for anything unfamiliar.
Additional security
To increase the security of your account, remove your password or require two steps to sign in.
Passwordless account
OFF
Turn on
Two-step verification
ON
Turn off
App passwords
Create a new app password
Sign out everywhere
If you think someone might have unauthorized access to your account, we can protect you by signing you out from your trusted devices. You'll be signed out of browsers, apps and anywhere else your account is used to sign in, where possible, within 24 hours.
Windows Hello lets you sign in to your device apps, online services and networks using your face, fingerprint or a PIN.
Reset Windows Hello on all of my Windows devices
Security page Sign out everywhere section with a confirmation dialog; signs out all devices within 24 hours
Don't stop at the password
Troubleshooting & FAQs
Which path should I use?
The hacker changed my password — can I still get in from a signed-in session?
Microsoft won't verify me on the recovery page.
The attacker changed my recovery phone and email — can I still recover?
How long does the account recovery form take?
What to do next
If you got back in ✅
Find out what they touched
Lock it down properly
If you couldn't recover it ⚠️
Why this keeps happening on free email
Rebuild on an inbox that's private by default
Proton Mail, VPN, Pass and Drive in one encrypted, Swiss-based plan — end-to-end encrypted, no ads, no tracking.
- End-to-end encrypted
- Swiss-based, no ads
- One plan, every app




- Move your other accounts over. Anywhere you used the old address to sign in or to reset passwords — banking, shopping, social media — change that password and set your new Proton address as the account email and recovery contact, so the lost inbox can't be used to take them too.
- Warn your contacts. Tell friends, family and colleagues that messages from the old account may not be you, and to ignore any requests for money, codes or links.
- Watch for misuse. Turn on alerts where you can and keep an eye on anything that was tied to the old address.
A different inbox affected?
Was this guide helpful?
Know someone who needs this? Send them the guide.
Written by
Jordan DicksonFounder, CyberSecurityGuides
Founder of CyberSecurityGuides, writing practical, jargon-free guides that help everyday people recover from and protect against online attacks.
Reviewed by CSG Security Engineers
