Additional Microsoft Defender tools and services that provide security across various platforms and environments
For a hacked Microsoft account where the attacker changed the primary email and password, recovery is only possible through the official self-service flows; support agents cannot manually verify ownership, change account details, or send password reset links.
Follow these steps end-to-end:
- Use the hacked/compromised account guide
- Go through the steps in How to recover a hacked or compromised Microsoft account:
- Run a full antivirus/malware scan on all PCs and devices used to sign in, as described in Step 1 of the guide, before attempting recovery again.
- Then try to reset the password using the official flow: reset your password.
- Go through the steps in How to recover a hacked or compromised Microsoft account:
- Use the Sign-in Helper first
- Before the recovery form, use the Sign-in Helper tool referenced in the recovery-form article: Sign-in Helper.
- This can sometimes route through alternative verification paths if any valid security info remains.
- Fill out the Microsoft account recovery form as completely as possible
- If normal reset and Sign-in Helper fail, use the Account recovery form: Account recovery form.
- Do this from a device and location previously used to sign in to the account (same PC/phone, same home or office network) to improve the automated checks.
- Provide a working contact email (any account that can be accessed, including a new temporary Outlook.com address created via Create one on the sign-in page). This contact email is only used to send recovery results.
- Include every detail known about the account when prompted (original email, purchase details, dates, etc.). The system uses these signals, but there is no separate manual channel to submit “extra” proof beyond the form.
- After submitting the recovery form
- Results are sent to the working contact email within 24 hours.
- If the result says the account could not be verified, it is allowed to:
- Try again, up to two times per day, ideally from the same known device/location and with any additional details remembered.
- If the account is verified, instructions to sign back in will be sent to the same working email.
- If security info was fully replaced by the attacker
- As reflected in multiple moderator answers, if the attacker has changed the security info (recovery email/phone, 2FA methods) and the automated recovery form repeatedly fails, there is no additional manual or support-based method to override the system or force recovery. In that case, the account is effectively unrecoverable.
- After regaining access
- Immediately:
- Change the password to a strong, unique one.
- Review and remove any unknown aliases or forwarding rules (connected accounts, forwarding, automatic replies) as described in the hacked-account guidance.
- Then follow How to help keep your Microsoft account safe and secure to add more security methods and make future recovery easier.
- Immediately:
There is no escalation path for manual verification beyond these documented tools; all recovery decisions are made by the automated systems based on the information entered and the signals from devices/locations.
References:
- Help with the Microsoft account recovery form
- How to recover a hacked or compromised Microsoft account
- What happens if there's an unusual sign-in to your account
- My account got hacked - Microsoft Q&A
- My account got hacked. - Microsoft Q&A
- Need help with hacked microsoft account - Microsoft Q&A
- Entraron a mi cuenta de microsoft y cambiaron el gmail y contraseña - Microsoft Q&A
- Me robaron una cuenta - Microsoft Q&A