Why it is so easy for anyone with only basic knowledge to take full control over other's Microsoft account?

Shafqat Khan 25 Reputation points
2025-09-11T16:03:40.12+00:00

My question is very basic, as I am facing the issue since many years now, every month I had to reset my password regularly - I do use the Microsoft's two factor authenticator app and still anyone can login to my Outlook account? I mean how is it even possible? I guess it is the time to say good bye to Outlook as we did to Yahoo and MSN and AOL a decade ago. I have some very serious trust issues now. I use Microsoft Outlook for some reason and I cannot simply delete my account but where's the user security & privacy at Outlook???

Outlook | Web | Outlook.com | Account management, security, and privacy

Locked Question. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

Answer accepted by question author
Kal-D 7,375 Reputation points Microsoft External Staff Moderator
2025-09-11T20:40:35.3733333+00:00

Dear Shafqat Khan,

Thank you for reaching out to the Q&A Forum!

I understand your concerns about unauthorized access to your Outlook account. I know how frustrating and concerning this must be, especially given your consistent use of Microsoft Authenticator for two-factor authentication (2FA). Microsoft take user security and privacy very seriously, and I’m here to help you secure your account and address this issue promptly.

The fact that you’re experiencing repeated unauthorized access despite 2FA suggests potential vulnerabilities such as session token theft, compromised third-party app permissions, or phishing attempts that may bypass standard security measures. Below, I’ve outlined a step-by-step plan to secure your account and prevent further issues, based on Microsoft’s recommended best practices for personal accounts like Outlook.com. Please perform these actions from a trusted, secure device.

  1. Run a Malware Scan:
    • Before making changes, ensure your devices are free of malware, which could capture session tokens or authentication codes.
    • On Windows, open Windows Defender (search “Virus & threat protection” in the Start menu), select “Scan options,” and run a “Full scan.”
    • Ensure your operating system and applications are fully updated to patch any vulnerabilities.
  2. Update Your Password:
    • Visit account.microsoft.com and sign in. Navigate to “Security” > “Change password” and create a strong, unique password (minimum 12 characters, including letters, numbers, and symbols). Do not reuse any previous passwords.
    • If you’re unable to log in, use the “Forgot password” option on the login page to reset it.
  3. Sign Out of All Sessions:
    • Go to Security, select “Sign-in activity,” and review recent logins for unfamiliar activity.
    • Click “Sign out all” or “Secure your account” to terminate all active sessions. Additionally, under “Devices,” remove any unrecognized devices linked to your account.
  4. Review Connected Apps:
    • Navigate to Security > “Privacy” > “Apps & services” to check for third-party applications with access to your account via OAuth.
    • Revoke access to any unfamiliar or suspicious apps, as these can sometimes allow unauthorized access without triggering 2FA.
  5. Check Email Settings:
    • In Outlook web (outlook.com), go to Settings > Mail > Forwarding and disable any unauthorized forwarding rules.
    • Also review “Rules” for any settings added by an unauthorized user.
  6. Strengthen 2FA and Recovery Options:
    • If you use older email clients with IMAP/POP, disable app-specific passwords and switch to modern authentication (OAuth). For enhanced security, consider adding a hardware security key (e.g., YubiKey) if supported.
  7. Monitor and Report Ongoing Issues:
    • Regularly check your sign-in activity at account.microsoft.com/security for the next few weeks.
    • If unauthorized access persists, please contact Microsoft Support at support.microsoft.com/contactus (select “Account & billing” > “Hacked account”) for further investigation.

Additional Notes

Microsoft is committed to protecting your account with robust security measures, including 2FA and continuous monitoring. However, threats like phishing, malware, or compromised third-party apps can sometimes exploit user-end vulnerabilities. By following the steps above, you can significantly reduce these risks.

If, after securing your account, you still feel uncomfortable continuing with Outlook, I understand your concerns. Should you choose to keep your account active for essential purposes, you can migrate non-critical data to another provider while maintaining these enhanced security measures.

Please let me know how these suggestions work for you, or if you'd like assistance in navigating Microsoft's support channels.

Warm regards.

==========================================================

If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".  

Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

Was this answer helpful?

2 people found this answer helpful.
0 comments No comments

2 additional answers

Sort by: Most helpful
  1. Shafqat Khan 25 Reputation points
    2025-09-14T11:34:57.9066667+00:00

    Thank you for your time and a detailed response. I will reply with the shortest response this time, as I have found a solution, I recommend everyone who is facing such issues. Please move to "Passwordless". My issue has been resolved since then. I will also recommend everyone to please go trough the above steps and turn on "Passwordless" option under your account "Security".

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  2. Eric Middleton 0 Reputation points
    2026-08-26T11:40:32.9966667+00:00

    When needed cancel your account. The normal users are easy to hack as they follow the Microsoft security plan for two factor authentication and then let block the owner for even changing the password. Microsoft lets the hackers own the Account owner and get all the files. All the real work is on the paid customer how owns the account.

    Was this answer helpful?

    0 comments No comments