Managing personal Outlook.com account settings, security, and privacy
There is no manual verification path (ID upload, support override, or agent bypass) to skip the 30‑day security info replacement period for a personal Microsoft account.
For consumer Microsoft accounts, recovery and security-info changes are fully automated for security reasons. When both the password and all configured second factors (like Microsoft Authenticator) are unavailable and the flow requires selecting “I don’t have any of these”, the system enforces the 30‑day security info replacement hold. This waiting period cannot be shortened or overridden by support agents.
The only supported options in this situation are:
- Try to regain access to an existing security method
- If any old security info (phone, alternate email, authenticator on another device) can be recovered, use it instead of choosing “I don’t have any of these”. As long as at least one existing method is usable, it is possible to:
- Sign in.
- Go to the Advanced security options page.
- Add a new way to sign in or verify (new phone/email/app) and confirm it.
- Remove the outdated method.
- This avoids triggering the 30‑day replacement hold.
- If any old security info (phone, alternate email, authenticator on another device) can be recovered, use it instead of choosing “I don’t have any of these”. As long as at least one existing method is usable, it is possible to:
- If all security info is truly unavailable
- Begin sign-in to the Microsoft account and, at the Verify your identity prompt, select I don't have any of these.
- Follow the instructions to replace the security info.
- After that, the account is placed in a 30‑day restricted state before sign-in is allowed.
- During those 30 days, if the old security info is found again, it can still be used to sign in, but doing so cancels the pending security-info update.
- If the password is also forgotten and no security info is usable
- Use the password reset flow and, when no verification option is available, follow the guidance to use the sign-in helper tool or the account recovery form.
- Provide as much accurate information as possible (past passwords, contacts, subjects, etc.). If successful, the same 30‑day security-info replacement period still applies.
Because the 30‑day hold is a security safeguard, there is no supported way to bypass it even if the primary recovery email is accessible.
References: