How long does it take for an ATO investigation to get dealt with by the Microsoft Account Security Team?

James Hall 0 Reputation points
2026-06-08T12:07:36.6666667+00:00

28 Days ago I had my Microsoft Account hacked (with them changing all my security details, log in email, deleting my passkey etc, all from one 2 digit number they phished from me from my MAuth App;), and about 30mins from the moment I found out I managed to get my Account Take Over request sent to Microsoft and apparently my account locked with help by web chat. Pretty much as soon as possible after navigating through non-helpful AI who sent me in circles, looking through articles to get some human help and getting to an agent who sent me the right way to the ATO form.

About a week in I made a new web chat ticket to ask about any progress (as I hadn’t had any email reply, not even in Junk email after my initial "We have thoroughly investigated the account and billing activity associated with your Microsoft account. Based on this review, we’ve confirmed that unauthorised access occurred." and nothing in Spam from Microsoft on the same email (and the one attached to the email of the account I’m trying to recover))
Then and again 14 days in. Both times they said the ATO ticket is still up and waiting for someone at MAS to deal with it. Guess what still waiting after 28 days, I feel if I ask web chat again my response will be to "be patient and keep waiting" as that is all I can do according to them.

Are Microsoft Account security really that understaffed that it can take over a month / months to deal with ATO investigations?

I literally have had nothing I can do about it for the past month whilst I constantly wait so I can re-verify my login for my PC, Office, Minecraft, Xbox, OneDrive etc. I've been told not to make any new ATO tickets, My account is over 10 years old, rather have some response about any progress then well what feels like being ghosted by support for a month. I had lost my passkey access on a different account from another company before (due to a my phone being hardware reset from a repair), they got it sorted within 48 hours.

I'm surprised it is taking more than 28 days from a big company like Microsoft for a non-guarenteed promise of a response in the future on something as simple as either an account rollback to like the day before I lost access or at least someone from the team to even ask about my MAuth token for that hacked account (which someone from webchat told me to keep on my device).

It had been secured by my MAuth and Passkey, you would hope that if someone tried accessing your account from a different IP, that "passwordless" (as recommended by Microsoft I'll add) wouldn't apply there, or whenever deleting a passkey or MAuth, that it would ask for those tokens again before getting deleted, but nope totally bypassed by a single 2 digit number request and email address.

Sorry for my long winded "question", you can probably tell I'm both fed up and tired of waiting for support on this from MAS.

I guess the TL:DR is: "How long does it take for MAS to deal with an ATO investigation?" ... it clearly seems to be more than 28 days, and "What else I can do in the meantime to maybe expedite this process whilst this account is supposedly locked?"

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Oldest
  1. AI answer

    2026-06-08T12:08:04.0566667+00:00

    The provided context does not state any specific or guaranteed timeline for Microsoft Account Security (MAS) handling an Account Takeover (ATO) investigation, nor any way to expedite it beyond the standard recovery and security-info flows.

    From the context, only these time-related points are documented:

    1. 30‑day security-info change restriction
      If all security info on a Microsoft account was removed and replaced, the account goes into a restricted state for 30 days before the new info takes effect. During this period:
    • Access to some sensitive actions and data is blocked.
    • The 30‑day period cannot be expedited, except by canceling the security-info change if that option is available and the change was initiated by the legitimate owner. See details in the “Security info change is still pending” documentation:
      • When all security info is removed, the account is restricted for 30 days.
      • Microsoft explicitly states: “We can't expedite the 30‑day process unless you cancel the request.”
    1. What can be done during the 30‑day period
      During this 30‑day restriction, some services remain usable (for example, signing in to Xbox, Skype, Outlook.com, OneDrive), but sensitive actions like changing password, parental controls, aliases, payment options, or accessing OneDrive Personal Vault are blocked until the 30 days end or the request is canceled.
    2. Cancel or report unauthorized security-info changes
      If the account shows the “Your security info change is still pending” / “You can’t access this site right now” message, the documented options are:
    • If the owner initiated the change and still has access to the old security proofs, use “cancel this request” on the pending window to stop the 30‑day change.
    • If the owner did not make the change and suspects compromise, use the “let us know” link on the same window to report unauthorized changes.
    1. Account recovery form processing
      For the Microsoft account recovery form (used when access is lost and security info is changed), the only documented timing is:
    • Microsoft sends the result of the recovery request to the working email provided within 24 hours of each submission.
    • If verification fails, the form can be retried up to two times per day. There is no additional documented SLA for deeper MAS/ATO investigations beyond this automated recovery flow.
    1. No documented way to accelerate MAS handling
      The context includes several Q&A cases where:
    • Users with compromised accounts are directed to the standard recovery article and the account recovery form.
    • Moderators explicitly state that if the recovery form and security-info flows do not succeed (for consumer accounts), there is no other supported method to recover the account, and support cannot bypass these processes. For tenant/admin scenarios (like losing access to all MFA methods for admin accounts), escalation through support and the Data Protection team is possible, but the context only describes that it can take multiple days and involves manual verification and engineering review. No fixed SLA is given.

    Given this, the only supported actions in the meantime, based on the context, are:

    1. If the account shows “security info change is still pending”:
      • Sign in to the Security page.
      • On the “Your security info change is still pending” window:
        • Use “cancel this request” if the security-info change was initiated by the legitimate owner and the old proofs are still accessible.
        • Use “let us know” if the change was not made by the owner, to route through the unauthorized-change flow.
    2. If locked out and using the recovery form:
      • Continue using the Microsoft account recovery form as documented in Help with the Microsoft account recovery form.
      • Expect a result email within 24 hours of each submission.
      • If not verified, retry with as much accurate historical information as possible, up to two times per day.
    3. For compromised Microsoft 365 / Entra ID / Defender scenarios (work or school accounts):
      • Use the documented investigation and remediation steps in Defender and Entra (sign-in logs, audit logs, message trace, restricted users, etc.) to secure the account and environment once access is regained.

    The context does not provide any official maximum duration or escalation path that would guarantee faster handling of an ATO investigation for a personal Microsoft account beyond these mechanisms.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.