Managing personal Outlook.com account settings, security, and privacy
For a Microsoft/Outlook.com account with 2FA enabled, recovery is limited to the automated flows and available security info. When 2FA is on and none of the second‑factor methods can be used reliably, support cannot manually override this for security reasons.
Based on the documented flows, these are the only supported options:
- If at least one security method still works
- Go to the Advanced security options page of the Microsoft account and sign in using the working method (email, phone, or app) if possible: Sign in.
- Select Add a new way to sign in or verify and add a new phone/email.
- Confirm it with the code sent, then expand the old, inaccessible method and select Remove.
- Do not remove all methods at once, or the account may be restricted for 30 days: what-does-security-info-change-is-still-pending-mean.
- If all security info is inaccessible but the password is known
- Start sign‑in at Sign in.
- At the Verify your identity prompt, choose I don't have any of these.
- Follow the prompts to replace the security info.
- After replacement, there is a mandatory 30‑day wait before normal sign‑in is allowed. During this period, using the old security info (if it becomes available) cancels the update.
- If the password is not known and 2FA is enabled
- Use the Microsoft account recovery form only if 2FA is not turned on or if at least one verification method is still usable. The documentation explicitly states:
- If 2FA is turned on and none of the alternate verification methods can be accessed, support agents cannot reset the password or change account details. The automated systems cannot be bypassed.
- The recovery form is here: Account recovery form, but it will not override 2FA when no second factor is available.
- Use the Microsoft account recovery form only if 2FA is not turned on or if at least one verification method is still usable. The documentation explicitly states:
- When repeatedly seeing “There’s a temporary problem with the service”
- The documented guidance is to try again later and, if locked out due to too many attempts, wait for the lockout to expire before trying again.
- Since different devices, networks, and browsers have already been tried and the error persists for months, this indicates a backend condition that the self‑service flows cannot override.
Given the constraints in the documentation:
- If no 2FA method (phone, email, authenticator, or recovery code) can be used successfully, and the I don’t have any of these path cannot be completed due to service errors, there is no additional supported self‑service or support‑driven path to regain access.
- Support agents are not allowed to send password reset links or alter security info for consumer accounts when 2FA is enabled and no verification method is available.
The only actions that remain within the documented process are:
- Continue to periodically retry the I don’t have any of these flow when signing in, in case the backend error is transiently resolved.
- If at any point a working 2FA method (old phone number, recovery code, or trusted device) becomes available again, immediately sign in, add new security info, and then remove the obsolete methods.
If none of the above becomes possible, the documentation does not provide an alternative way to recover the account.
References: