Urgent: Account locked out - Lost Password & Authenticator, only have Primary Email (Forced 30-day wait)

Cao Thien Son 0 Reputation points
2026-04-29T03:53:57.6166667+00:00

I am in a critical situation with my personal Microsoft account. I changed my password yesterday and unfortunately forgot the new one. Compounding this, I have lost access to the device hosting my Microsoft Authenticator app.

I DO have full, verified access to my primary recovery email (Gmail) and can receive security codes there.

Because I lost both the password and the Authenticator, using the "Forgot Password" flow with my recovery email eventually forces me to select "I don't have any of these" for the second factor. This triggers a mandatory 30-day security info replacement period.

Given that I have control over the primary recovery email, is there any manual verification process (providing ID, verifying account history) to reset the password and bypass the 30-day lock? I am desperate to regain access for my studies.

Outlook | Web | Outlook.com | Account management, security, and privacy
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-04-29T03:54:19.3766667+00:00

    There is no manual verification path (ID upload, support override, or agent bypass) to skip the 30‑day security info replacement period for a personal Microsoft account.

    For consumer Microsoft accounts, recovery and security-info changes are fully automated for security reasons. When both the password and all configured second factors (like Microsoft Authenticator) are unavailable and the flow requires selecting “I don’t have any of these”, the system enforces the 30‑day security info replacement hold. This waiting period cannot be shortened or overridden by support agents.

    The only supported options in this situation are:

    1. Try to regain access to an existing security method
      • If any old security info (phone, alternate email, authenticator on another device) can be recovered, use it instead of choosing “I don’t have any of these”. As long as at least one existing method is usable, it is possible to:
        1. Sign in.
        2. Go to the Advanced security options page.
        3. Add a new way to sign in or verify (new phone/email/app) and confirm it.
        4. Remove the outdated method.
      • This avoids triggering the 30‑day replacement hold.
    2. If all security info is truly unavailable
      • Begin sign-in to the Microsoft account and, at the Verify your identity prompt, select I don't have any of these.
      • Follow the instructions to replace the security info.
      • After that, the account is placed in a 30‑day restricted state before sign-in is allowed.
      • During those 30 days, if the old security info is found again, it can still be used to sign in, but doing so cancels the pending security-info update.
    3. If the password is also forgotten and no security info is usable
      • Use the password reset flow and, when no verification option is available, follow the guidance to use the sign-in helper tool or the account recovery form.
      • Provide as much accurate information as possible (past passwords, contacts, subjects, etc.). If successful, the same 30‑day security-info replacement period still applies.

    Because the 30‑day hold is a security safeguard, there is no supported way to bypass it even if the primary recovery email is accessible.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.