Sasha,
I misunderstood that you were (are?) apparently a Microsoft employee.
However, I'd think you'd then know that as a link Don Varnau provided in his post back on Page-10 of this thread mentions, Microsoft [Support] employees aren't allowed to reset or otherwise change account access manually anymore (if they ever were?) to protect from abuse, so there's simply no way any longer to recover an account that's had all of the original security verification information modified.
What this situation makes me wonder though, is had you entered and kept the Recovery code for that hacked account and if so, was this also useless in regaining control of the account?
I ask because I've wondered how Microsoft is allowing all of the previous security information to be changed without any delay, since this obviously is a suspicious situation and really shouldn't be allowed, let alone simply locking any future changes or account access for 30 days.
Also, did you have a Windows device using Windows Hello (Face, Fingerprint, maybe PIN?) associated with the account, since it appears from some threads I've seen that this may allow the account to be accessed even after the security items have been changed and enabled the original owner to change them back, albeit with the 30-day lockout I mentioned. I'm less certain of this possibility, but just wondered whether you had Windows Hello enabled with the account or not?
I've personally got not only Windows Hello Face with the Microsoft Surface Go I use to access the account, but also the Recovery code, in hopes that combined with the other historical information I know related to the account might be enough to recover using the form if I ever lost account control.
From your description, it sounds more like you might have an issue with the 2FA portion than the original hack itself, but if you're unable to change any of the alternate verification information in order to get 2 forms of identification to reach the 2FA threshold, that might end in a lockout situation that can't be resolved regardless?
Just trying to fully understand the potential risks when using 2FA that I may not have already recognized, which is why I'd personally set things like the recovery code years ago, along with the more commonly used email and phone number options and kept all of them current.
Rob
< EDIT > Also, did you ever disable the ability to "Let devices and apps use POP or IMAP in the Outlook.com, Settings, Mail, Sync email configuration?
I mention this, because at least in the past, this was one method hackers were using to brute force passwords into accounts with 2FA enabled, since POP and IMAP don't support MFA capabilities. However, you'd likely have seen these attempts in the activity tracking if you monitored that around the time when your hack occurred.