How to Secure Your Outlook / Hotmail Account

    Lock down your Microsoft Outlook or Hotmail account with robust security settings, MFA, and privacy controls.

    JDCS
    By Jordan Dickson · Reviewed by CSG Security Engineers

    Updated June 2026 · 6 min read

    Your Outlook or Hotmail inbox is the master key to the rest of your online life — it can reset the password on almost every other account you own, so it’s worth making genuinely hard to break into. This walkthrough locks it down properly: two-step verification so a stolen password alone isn’t enough, a saved recovery code so you’re never locked out, a strong and unique password, and tightened recovery and sign-in methods. It doubles as post-recovery hardening, too, if you’ve just got back in.

    Good to know

    Your Outlook / Hotmail sign-in is your Microsoft account — so locking it down also protects OneDrive, Office, Xbox and everything else tied to it.
    Affiliate disclosure: if you create or upgrade a paid Proton plan through links on this page, CyberSecurityGuides may earn a commission at no extra cost to you. We only recommend tools we use and trust.

    How to lock down your Outlook account

    1

    Sign in and open your sign-in settings

    Do all of this from a device and browser you trust. Sign in to your Microsoft account at account.microsoft.com, open the Security tab, then choose Manage how I sign in. This is the page where two-step verification, your recovery code and your sign-in methods all live — you’ll spend most of this guide here.
    Microsoft

    Sign in

    yourname@outlook.com

    Password

    Sign in

    Signing in to account.microsoft.com, opening the Security tab and Manage how I sign in, landing on the additional security page

    2

    Add an authenticator app

    An app-based code is the strongest everyday second step — it’s generated on your device and can’t be SIM-swapped like a texted one. On the Ways to prove who you are list, choose Add a new way to sign in or verify, then Use an app. Microsoft suggests its own app first — pick set up a different Authenticator app if you’d rather use Proton Authenticator or another app.

    Open your authenticator app, scan the QR code Microsoft shows, then type the 6-digit code your app generates and choose Next. This adds the authenticator as a verification method — in the next step you’ll switch on two-step verification to make it required on every new sign-in.

    Microsoft accountYour infoPrivacySecuritySubscriptionsDevices
    Security

    Change password

    Last update: 4/24/2025

    Change ›

    Two-step verification

    OFF

    Manage ›

    Ways to prove who you are

    Manage sign-in and verification options for your Microsoft account.

    Enter password Up to date
    Email a codeyourname@outlook.com Up to date
    + Add another way to sign in to your account

    Additional security

    To increase the security of your account, remove your password or require two steps to sign in.

    Passwordless account

    OFF

    Turn on

    Two-step verification

    OFF

    Turn on

    Ways to prove who you are, Add a new way to sign in or verify, Use an app, set up a different authenticator app, scanning the QR code and entering the verification code

    We recommend Proton Authenticator

    Strong one-time codes that can't be SIM-swapped like a text message — free, open-source, and they stay on your device.

    Set it up in 5 minutes
    3

    Turn on two-step verification

    Adding the authenticator made a strong second step available — now make it required. Scroll down to Additional security and, under Two-step verification, choose Turn on. Microsoft confirms it using the app you just set up.

    Once it’s on, every sign-in on a device Microsoft doesn’t recognise needs your password and a code from your authenticator — so a stolen or guessed password is no longer enough on its own.
    Microsoft accountYour infoPrivacySecuritySubscriptionsDevices
    Security

    Change password

    Last update: 4/24/2025

    Change ›

    Two-step verification

    OFF

    Manage ›

    Ways to prove who you are

    Manage sign-in and verification options for your Microsoft account.

    Enter password Up to date
    Email a codeyourname@outlook.com Up to date
    Enter a code from an authenticator app Up to date

    Additional security

    To increase the security of your account, remove your password or require two steps to sign in.

    Passwordless account

    OFF

    Turn on

    Two-step verification

    OFF

    Turn on

    Security page Additional security section, turning on Two-step verification using the authenticator app you added

    First, keep Passwordless account off

    In the same Additional security section, check that Passwordless account is OFF before you turn this on. Passwordless sign-in — using just a passkey, the app or a PIN — is convenient and can be secure, but it drops your password as a factor. Keeping a strong password and layering two-step on top means anyone trying to break in needs two separate things, which is harder to beat than a single passwordless method. You can always go passwordless later if you prefer.

    Some mail clients will need an app password

    Once two-step is on, any app that can’t handle a verification code — typically an older desktop or third-party mail client set up with basic IMAP/POP — will be blocked from your inbox until you create an app password and use it in that client in place of your normal password. Microsoft’s wizard flags this and links to it, and you can create one any time from the security page. Modern apps (the Outlook app, or Apple Mail set up fresh) use modern sign-in and won’t need one — so prefer those where you can.
    4

    Save your recovery code

    With two-step on, you need a guaranteed way back in if you ever lose your authenticator. Scroll down to Recovery code and choose Generate a new code. Microsoft shows a 25-character code once — print it or save it somewhere safe and offline (a password manager’s notes, or paper in a drawer).

    Treat it as a one-time, emergency-only code: it’s there for the day you’ve genuinely lost every other way in, and using it consumes it — you’ll need to generate a fresh one afterwards. Don’t reach for it during everyday sign-in.
    Microsoft accountYour infoPrivacySecuritySubscriptionsDevices

    Additional security

    Passwordless account

    OFF

    Turn on

    Two-step verification

    OFF

    Turn on

    Sign out everywhere

    Sign out everywhere

    Recovery code

    You can use this code to access your account if you lose access to your sign-in info. Print this out and keep it in a safe place or take a picture of it.

    Generate a new code

    Generating and saving the 25-character Microsoft account recovery code

    5

    Set a strong, unique password

    Your password is the first layer — make it count. Back on the Security page, expand Enter password and choose Change password, then set one that is long (16+ characters) and used nowhere else. Reusing a password means one leak on another site can open your inbox; a unique one keeps this account’s front door yours alone.

    Don’t try to invent or memorise it — let a password manager generate and store a long, random one for you. We recommend Proton Pass: it creates a unique password for every account and fills it in automatically, so ‘long and unique’ costs you no effort to keep up.
    Microsoft accountYour infoPrivacySecuritySubscriptionsDevices
    Security

    Change password

    Last update: 4/24/2025

    Change ›

    Two-step verification

    ON

    Manage ›

    Ways to prove who you are

    Manage sign-in and verification options for your Microsoft account.

    Enter password Up to date
    Email a codeyourname@outlook.com Up to date
    Enter a code from an authenticator app Up to date

    account.microsoft.com Security, Change password, entering a strong new password and saving

    We recommend Proton Pass

    Generate and remember a long, unique password for every account — free, open-source, and end-to-end encrypted.

    Set up Proton Pass
    6

    Review your recovery and sign-in methods

    Open Ways to prove who you are and aim for two strong methods: your authenticator app (from step 2) plus Email a code sent to a secure email you control on a different provider. The authenticator is your everyday second step; the email is your backup if you ever lose the app — and it’s how Microsoft warns you of unusual activity and gets you back in.

    With those two in place, remove Text a code (SMS) if it’s listed. Text messages can be intercepted or SIM-swapped, so it’s the weakest way to prove it’s you and you no longer need it — expand the method and choose Remove.
    Microsoft accountYour infoPrivacySecuritySubscriptionsDevices
    Security

    Change password

    Last update: 4/24/2025

    Change ›

    Two-step verification

    ON

    Manage ›

    Ways to prove who you are

    Manage sign-in and verification options for your Microsoft account.

    Enter password Up to date
    Text a code+•• ••• ••67 Up to date
    Enter a code from an authenticator app Up to date
    + Add a new way to sign in or verify

    Ways to prove who you are page, expanding the Text a code (SMS) method and removing it, leaving the authenticator and recovery email

    Can't remove it?

    Microsoft won’t let you remove a method if it would leave you with too few ways to prove who you are. If Remove is greyed out or blocked, add another method first — your recovery email is ideal — then remove Text a code.

    We recommend Proton Mail

    Your recovery pathway is only as secure as the email it's attached to. For maximum security, we recommend an end-to-end encrypted inbox.

    Why switch to Proton Mail

    Frequently asked questions

    Which two-step method is safest?
    An authenticator app is the strongest common option — the codes are generated on your device and can't be SIM-swapped the way a texted code can. Keep a text or email code only as a backup, not your main method.
    What if I lose my phone or authenticator?
    That's exactly what your recovery code and recovery email are for. Keep the 25-character recovery code somewhere safe and add a recovery address you control — with either, you can get back in.
    Do I still need a strong password if two-step is on?
    Yes. Two-step is a second layer, not a replacement. A long, unique password (ideally from a password manager) keeps the first layer strong if your second factor is ever bypassed.
    Will turning on two-step break my mail apps?
    Modern apps — the Outlook app, or Apple Mail set up fresh — handle it fine. Only very old apps need an 'app password', and those bypass two-step, so it's better to switch to an app that supports modern sign-in.

    What to do next

    Go further: an inbox that's private by default

    You've made Outlook much harder to break into — but it's still a giant target whose contents Microsoft can read. An end-to-end encrypted inbox like Proton Mail is the next step up: your mail is encrypted so only you can read it, recovery runs through methods you control, and there are no ads mining your messages.
    Why switch to Proton Mail

    Worried you're already compromised?

    Locking the account down is half the job. If you suspect someone may have already been in, run the full compromise check — it finds and undoes the quieter traps an intruder leaves behind: rogue forwarding, hidden inbox rules, connected apps, extra aliases and unfamiliar devices.
    See the signs your Outlook is hacked

    Locking down other accounts?

    These steps apply to any inbox — here's the complete email-security guide.
    Secure any email account

    Was this guide helpful?

    Know someone who needs this? Send them the guide.

    JD

    Written by

    Jordan Dickson

    Founder, CyberSecurityGuides

    Founder of CyberSecurityGuides, writing practical, jargon-free guides that help everyday people recover from and protect against online attacks.

    Reviewed by CSG Security Engineers

    More from Email Security