Unknown email address added to my Microsoft account after suspicious activity – account secured, but verification email still pending removal

Redstone Logi 0 Reputation points
2026-04-28T16:48:44.1966667+00:00

Hello,

I recently detected suspicious activity on my Microsoft account. An unknown person added an alternative verification email address to my account without my permission.

The email address that was added is: ******@imparml.ru

I did NOT create or authorize this email address. It appears to be a temporary/disposable email service.

After noticing the activity, I immediately secured my account by:

  • changing my password
  • changing my sign-in email address
  • removing unknown devices
  • enabling and using my passkey / two-factor authentication
  • removing the unknown email address from my account

Microsoft now shows that my security information will be fully updated in 30 days.

My questions are:

  1. Is my account fully secure now?
  2. Can the previous verification email still be used to reset my password during the 30-day waiting period?
  3. Is there anything else I should do to ensure my account remains safe?

There has been no suspicious activity since I secured the account.

Thank you for your help.Hello,

I recently detected suspicious activity on my Microsoft account. An unknown person added an alternative verification email address to my account without my permission.

The email address that was added is:
*@imparml.ru

I did NOT create or authorize this email address. It appears to be a temporary/disposable email service.

After noticing the activity, I immediately secured my account by:

  • changing my password
  • changing my sign-in email address
  • removing unknown devices
  • enabling and using my passkey / two-factor authentication
  • removing the unknown email address from my account

Microsoft now shows that my security information will be fully updated in 30 days.

My questions are:

  1. Is my account fully secure now?
  2. Can the previous verification email still be used to reset my password during the 30-day waiting period?
  3. Is there anything else I should do to ensure my account remains safe?

There has been no suspicious activity since I secured the account.

Thank you for your help.

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Newest
  1. AI answer

    2026-04-28T16:49:02.86+00:00
    1. The account is largely secure now, but treat the 30‑day period as a heightened‑risk window. When all or most security info is changed, Microsoft places the account into a restricted state for 30 days to protect against unauthorized changes. During this time, the account remains usable (email, OneDrive, etc.), but security settings and billing info changes are limited.
    2. During the 30‑day waiting period, the old security info is still technically in place and used for notifications. Microsoft continues to send alerts to the original security info to warn that changes were made. The change to the new security info only takes effect after the 30 days. That is why Microsoft cannot expedite this period except by canceling the request. If the attacker’s address was part of the “old” security info set, it remains associated until the 30 days complete or the request is canceled.
    3. To keep the account safe during this period:
      • Check whether the account is in the “security info change is still pending” state and use the built‑in options on that page:
        • If the security‑info removal/change was initiated by you and you still have access to the original, legitimate security proofs, sign in to the Security page and, on the Your security info change is still pending window, select cancel this request and follow the prompts. This immediately stops the 30‑day replacement and keeps the old (legitimate) security info.
        • If you did not initiate the changes (or suspect any of them were done by the attacker), sign in to the Security page and, on the same Your security info change is still pending window, select let us know and follow the prompts so Microsoft can treat it as an unauthorized change.
      • Review recent sign‑in activity on the Recent activity page to confirm there are no ongoing unauthorized sign‑ins and to mark any unknown activity as “This wasn’t me.”
      • Avoid removing all security info at once in the future. When replacing security info, always add new methods first, then remove old ones, to avoid triggering the 30‑day restricted state.
      • Continue monitoring for unusual sign‑in alerts and emails. Legitimate security alerts from Microsoft about unusual activity or sign‑ins come from the Microsoft account team at the domain shown in the documentation.

    If no new suspicious activity appears in Recent activity and the pending security‑info change is either canceled (if you initiated it) or reported as unauthorized (if not), the account should remain protected while the 30‑day process completes.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.