Using Classic Outlook on Windows for personal email, calendar, and contact management
The automated loop and SMS failures are a direct result of Microsoft's Identity Protection risk engine actively blocking the session. When phone verification fails repeatedly—often due to international SMS short-code routing issues with regional carriers—the backend flags the activity as a brute-force attempt.
Consequently, the risk engine shadow-bans further attempts by silently looping the account recovery form. Furthermore, no human support agent possesses the backend Identity and Access Management (IAM) permissions to override a cryptographic lockout on a consumer @outlook.com account. Requesting a manual phone escalation is a structural dead end.
To bypass the automated gatekeeper and force the recovery form to actually process, you must feed the system clean telemetry:
- Halt all login attempts for a strict 24 hours. You must let the server-side rate limits and risk flags expire. Every failed attempt or SMS request resets this cooldown timer.
- Launch an InPrivate/Incognito browser window. This physically isolates your new session from the polluted SSO tokens and corrupted cache currently causing the redirect loop.
- Use a recognized network. Connect using a device and Wi-Fi network (like your home router) that has historically logged into this account. The automated system weighs IP and device telemetry heavily to verify identity.
- Go directly to
[account.live.com/acsr](https://account.live.com/acsr)and submit the recovery form exactly once.
You have to satisfy the automated security parameters. There is no manual human override or phone queue for consumer tenant lockouts.