A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
The supported recovery path is:
- Run a full malware scan before changing anything else. In Windows Security, open Virus and threat protection → Scan options → Full scan → Scan now. Microsoft recommends a full scan before changing the password on a compromised account.
- Use the Microsoft account Sign-in Helper first. For hacked accounts, this is the recommended starting point. It asks for the account email address or phone number and then either provides self-help steps or offers the option to talk to an agent.
- If the account still appears in sign-in, use the hacked-account recovery path. On the sign-in page, select Forgot my password and then choose I think someone else is using my Microsoft account.
- If the recovery form is needed, use a working contact email and wait for the result. The recovery form requires a working email address that can receive messages about the request. Microsoft sends the result within 24 hours. If the request is not verified, it can be retried up to two times per day.
- Important limitation: if two-step verification was turned on and none of the alternate verification methods are accessible, Microsoft states that support agents cannot reset the password or change account details.
- Support limitation: Microsoft support agents are not allowed to send password reset links or access and change account details. If Sign-in Helper offers contact with an agent, that is the official support route, but account recovery itself remains subject to those security limits.
- If access is restored, immediately review account settings. Check connected accounts, forwarding, and automatic replies, then change the password to a strong one.
Because the attacker changed both the password and the sign-in email, the correct process is still to start with the Sign-in Helper and then use the account recovery flow it provides. If the recovery form has already failed, it can be retried within the allowed limit. If two-step verification was enabled on the account and no verification methods are available, there is no supported manual bypass through support.