A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
When all security info (such as phone numbers used for verification codes) is removed and replaced, the Microsoft account goes into a restricted 30‑day security period. During these 30 days, the new phone number can’t be fully used for actions that require security codes, and the restriction cannot be bypassed.
Key points from the 30‑day pending period:
- The message “Your security info change is still pending” means all previous security info was replaced and the account is locked in a restricted state for 30 days.
- During this period, actions that require a security code (like changing security info again or accessing certain sensitive areas) are blocked.
- If two‑factor verification was turned on, there is no access to anything that requires that second factor until the 30 days are over or the pending change is canceled (if that option is available on the security page).
What can be done now:
- Continue to sign in to most Microsoft services that don’t require the blocked security verification, as allowed in the 30‑day period.
- If the security change was made personally and the option is shown, cancel the pending security‑info change so the old phone/security info becomes active again.
- Otherwise, wait until the 30‑day period completes; only then will the new phone number be usable for text verification.
There is no supported way to shorten or override this 30‑day security hold once it is in place.
References: