A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
The provided context does not state any specific or guaranteed timeline for Microsoft Account Security (MAS) handling an Account Takeover (ATO) investigation, nor any way to expedite it beyond the standard recovery and security-info flows.
From the context, only these time-related points are documented:
- 30‑day security-info change restriction
If all security info on a Microsoft account was removed and replaced, the account goes into a restricted state for 30 days before the new info takes effect. During this period:
- Access to some sensitive actions and data is blocked.
- The 30‑day period cannot be expedited, except by canceling the security-info change if that option is available and the change was initiated by the legitimate owner. See details in the “Security info change is still pending” documentation:
- When all security info is removed, the account is restricted for 30 days.
- Microsoft explicitly states: “We can't expedite the 30‑day process unless you cancel the request.”
- What can be done during the 30‑day period
During this 30‑day restriction, some services remain usable (for example, signing in to Xbox, Skype, Outlook.com, OneDrive), but sensitive actions like changing password, parental controls, aliases, payment options, or accessing OneDrive Personal Vault are blocked until the 30 days end or the request is canceled. - Cancel or report unauthorized security-info changes
If the account shows the “Your security info change is still pending” / “You can’t access this site right now” message, the documented options are:
- If the owner initiated the change and still has access to the old security proofs, use “cancel this request” on the pending window to stop the 30‑day change.
- If the owner did not make the change and suspects compromise, use the “let us know” link on the same window to report unauthorized changes.
- Account recovery form processing
For the Microsoft account recovery form (used when access is lost and security info is changed), the only documented timing is:
- Microsoft sends the result of the recovery request to the working email provided within 24 hours of each submission.
- If verification fails, the form can be retried up to two times per day. There is no additional documented SLA for deeper MAS/ATO investigations beyond this automated recovery flow.
- No documented way to accelerate MAS handling
The context includes several Q&A cases where:
- Users with compromised accounts are directed to the standard recovery article and the account recovery form.
- Moderators explicitly state that if the recovery form and security-info flows do not succeed (for consumer accounts), there is no other supported method to recover the account, and support cannot bypass these processes. For tenant/admin scenarios (like losing access to all MFA methods for admin accounts), escalation through support and the Data Protection team is possible, but the context only describes that it can take multiple days and involves manual verification and engineering review. No fixed SLA is given.
Given this, the only supported actions in the meantime, based on the context, are:
- If the account shows “security info change is still pending”:
- Sign in to the Security page.
- On the “Your security info change is still pending” window:
- Use “cancel this request” if the security-info change was initiated by the legitimate owner and the old proofs are still accessible.
- Use “let us know” if the change was not made by the owner, to route through the unauthorized-change flow.
- If locked out and using the recovery form:
- Continue using the Microsoft account recovery form as documented in Help with the Microsoft account recovery form.
- Expect a result email within 24 hours of each submission.
- If not verified, retry with as much accurate historical information as possible, up to two times per day.
- For compromised Microsoft 365 / Entra ID / Defender scenarios (work or school accounts):
- Use the documented investigation and remediation steps in Defender and Entra (sign-in logs, audit logs, message trace, restricted users, etc.) to secure the account and environment once access is regained.
The context does not provide any official maximum duration or escalation path that would guarantee faster handling of an ATO investigation for a personal Microsoft account beyond these mechanisms.
References:
- What does “Security info change is still pending” mean?
- Help with the Microsoft account recovery form
- Microsoft account has been locked
- Respond to a compromised cloud email account
- Address compromised user accounts with automated investigation and response
- Troubleshoot MFA voice call and SMS problems
- My personal hotmail account hacked by hacker with authentication app enabled. - Microsoft Q&A
- My account got hacked. - Microsoft Q&A
- How do I send an email to Microsoft about my account being hacked and taken over by <removed> ? - Microsoft Q&A
- my microsoft account has been compromised - Microsoft Q&A
- How Do I Regain Access to My Account After Losing Access to Microsoft Authenticator? (Urgent Request). - Microsoft Q&A