Managing personal Outlook.com account settings, security, and privacy
The described behavior matches an account that is effectively in a protected or blocked security state where most security-info operations (adding/removing methods, generating recovery codes, changing 2FA) are temporarily disabled and only limited actions (like signing in and changing the password) are allowed.
From the available guidance, there are only two supported paths to resolve this kind of situation for a personal Microsoft account:
- Use the built‑in recovery / security‑info flows and wait out any blocks For personal Microsoft accounts, security changes are tightly controlled and can be blocked for reasons such as unusual activity, high volumes of verification requests, or suspected compromised traffic:
- Repeated or excessive requests for verification codes (email/SMS) can cause temporary or even longer blocks where codes are not accepted or delivered, and operations fail with generic errors like “Something went wrong” or “There’s a temporary problem with the service. Please try again later.”
- In some cases, Microsoft will stop sending codes or invalidate existing ones until the block naturally expires.
- Avoid further repeated attempts (email/SMS/Authenticator) for several days to a week, because each burst of attempts can reset the timer on the block.
- Continue to sign in only when necessary using existing methods (email/SMS/PC sign‑in) and avoid changing security info during the cooling‑off period.
- If access to all security info is ever lost, the only supported path is to start the recovery flow by choosing “I don’t have any of these” at the “Verify your identity” step and follow the prompts to replace security info. Once replacement is initiated, there is a mandatory 30‑day waiting period before full access to security settings is restored. During this period, only limited actions are allowed and any attempt to change security info can be blocked until the 30 days elapse.
- If security info has been replaced or is pending replacement, wait the 30‑day period When all security info is replaced (or Microsoft treats the account as if security info is being replaced), the account enters a 30‑day “security info change is still pending” state. During this period:
- Most sensitive operations on the Security page are blocked, including:
- Updating password (in some cases)
- Updating account aliases
- Accessing parental controls
- Managing certain payment options
- Access to most consumer services (Outlook.com, OneDrive, Xbox, etc.) continues, but security‑sensitive changes are not allowed until the 30 days are over.
- If two‑factor verification is turned on, access to many of these sensitive areas is completely blocked until the pending period ends.
- Wait for the 30‑day period to complete; after that, security settings (including 2FA methods and recovery code generation) become available again.
- If the original security info becomes available again during the 30 days, it can still be used to sign in; doing so cancels the pending change and restores the previous security configuration.
- Most sensitive operations on the Security page are blocked, including:
If none of the above flows resolve the issue and the account remains unable to modify any security/2FA options, there is no additional self‑service mechanism documented for personal Microsoft accounts beyond these automated protections and waiting periods. For business or school accounts, an administrator or the Microsoft Data Protection team can intervene, but that path does not apply to personal Outlook.com / Microsoft accounts.
References: