Managing personal Outlook.com account settings, security, and privacy
If the attacker changed the primary alias and removed the original email, the immediate recovery path is to secure the Microsoft account and use Microsoft’s account recovery flow.
- Run a full malware scan on the PC before changing anything else.
- Open Windows Security.
- Go to Virus and threat protection.
- Select Scan options > Full scan > Scan now.
- This matters because Microsoft recommends clearing malware before changing the password.
- Change the Microsoft account password, or reset it if sign-in no longer works.
- After the malware scan, sign in and change the password.
- If sign-in fails, use the password reset flow.
- Check whether the account still shows any trusted sign-in or verification methods.
- Verification codes sent by email can only go to the primary alias or another email added as a way to verify sign-in.
- On the Security basics page, select Update info and review whether the listed email or phone details are still valid.
- Review recent account activity.
- Check the recent activity page to see when and where the account was accessed, including successful sign-ins and security challenges.
- Check account settings that attackers commonly change.
- Review connected accounts, forwarding, and automatic replies.
- If access is still possible, add a new alias and make it the primary alias.
- Sign in to the Microsoft account website.
- Go to Your info > Manage how you sign in to Microsoft.
- Select Add email or Add phone number.
- Set up and verify the new alias.
- Then make that alias the primary alias.
- Important: an alias already associated with another Microsoft account cannot be added.
- If the attacker’s changes prevent normal recovery, use the hacked-account recovery tool.
- Microsoft directs compromised-account recovery through the sign-in helper tool, which either provides self-help steps or offers the chance to talk to an agent.
- If verification codes are not arriving, check the correct mailbox and Junk folder.
- Valid Microsoft verification emails come from @accountprotection.microsoft.com.
- That domain is safe to trust.
- Mark @accountprotection.microsoft.com as a trusted sender if needed.
Important limitation: Microsoft support agents are not allowed to send password reset links or directly access and change account details. Recovery must go through the official recovery and sign-in flows.
- How to recover a hacked or compromised Microsoft account
- How to recover a hacked or compromised Microsoft account
- Change the email address for your Microsoft account
- "Something went wrong" with error ADDriverStoreAccessNonLocalException
- Help protect your Outlook.com email account
- Troubleshoot Microsoft verification code issues
- Can I trust email from the Microsoft account team?