A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
- The account is largely secure now, but treat the 30‑day period as a heightened‑risk window. When all or most security info is changed, Microsoft places the account into a restricted state for 30 days to protect against unauthorized changes. During this time, the account remains usable (email, OneDrive, etc.), but security settings and billing info changes are limited.
- During the 30‑day waiting period, the old security info is still technically in place and used for notifications. Microsoft continues to send alerts to the original security info to warn that changes were made. The change to the new security info only takes effect after the 30 days. That is why Microsoft cannot expedite this period except by canceling the request. If the attacker’s address was part of the “old” security info set, it remains associated until the 30 days complete or the request is canceled.
- To keep the account safe during this period:
- Check whether the account is in the “security info change is still pending” state and use the built‑in options on that page:
- If the security‑info removal/change was initiated by you and you still have access to the original, legitimate security proofs, sign in to the Security page and, on the Your security info change is still pending window, select cancel this request and follow the prompts. This immediately stops the 30‑day replacement and keeps the old (legitimate) security info.
- If you did not initiate the changes (or suspect any of them were done by the attacker), sign in to the Security page and, on the same Your security info change is still pending window, select let us know and follow the prompts so Microsoft can treat it as an unauthorized change.
- Review recent sign‑in activity on the Recent activity page to confirm there are no ongoing unauthorized sign‑ins and to mark any unknown activity as “This wasn’t me.”
- Avoid removing all security info at once in the future. When replacing security info, always add new methods first, then remove old ones, to avoid triggering the 30‑day restricted state.
- Continue monitoring for unusual sign‑in alerts and emails. Legitimate security alerts from Microsoft about unusual activity or sign‑ins come from the Microsoft account team at the domain shown in the documentation.
- Check whether the account is in the “security info change is still pending” state and use the built‑in options on that page:
If no new suspicious activity appears in Recent activity and the pending security‑info change is either canceled (if you initiated it) or reported as unauthorized (if not), the account should remain protected while the 30‑day process completes.
References:
- What does “Security info change is still pending” mean?
- Removing a sign-in verification method
- What happens if there's an unusual sign-in to your account
- Check the recent sign-in activity for your Microsoft account
- My account got hacked. - Microsoft Q&A
- My account got hacked - Microsoft Q&A
- Hacker set up continuous draft ransomware email - Microsoft Q&A
- Is this legit email also? - Microsoft Q&A