A security solution that detects identity-based threats and suspicious activities in on-premises Active Directory environments
Use the official Microsoft account recovery path only.
- Start with the hacked account flow in the sign-in helper tool. It asks for the email address or phone number and then either shows self-help steps or offers the chance to talk to an agent.
- If sign-in still fails, use the Microsoft account recovery form. Before submitting it:
- Use a working email account that can receive updates about the recovery request.
- Complete the form from a device previously used to sign in to the account, and from a familiar location such as home or office if possible.
- Provide as much accurate account history as possible.
- If the account shows verification options that are not recognized and two-step verification was not enabled, use the Sign-in Helper first.
- If two-step verification was enabled and none of the alternate verification methods are accessible, Microsoft states support cannot help recover the account. Support agents are not allowed to send password reset links or access and change account details.
- If access is regained, immediately:
- Run a full malware scan on the PC before changing the password.
- Change or reset the password.
- Review account settings such as connected accounts, forwarding, and automatic replies.
- Check the Security basics page, review recent activity, and mark suspicious activity with This wasn't me or Secure your account.
- About the suspicious verification address and prior security info: Microsoft support content states support agents are not allowed to access and change account details or send password reset links. The supported path is the sign-in helper and recovery form.
- About the existing support case: the documented support path is to use Contact Microsoft Support or the sign-in helper, which can route to the best support option. No documented process is provided here for case continuation specifics.
- If Microsoft sends account-team emails during recovery, email from the @accountprotection.microsoft.com domain is safe to trust. Verification can be checked by confirming that domain and, if needed, reviewing message headers.