How to secure Microsoft account after being hacked
If your Microsoft account has been compromised, the first priority is to regain control before the attacker changes recovery details, access tokens, or security settings.
This guide explains the fastest recovery steps and the controls that matter most for Microsoft services such as Outlook, OneDrive, Xbox, Microsoft 365, and Windows.
Account takeovers often happen quietly, which is why the strongest defense combines immediate recovery, device cleanup, and long-term hardening.
The goal is not only to get back in, but to make the account difficult to hijack again.
Confirm the compromise and assess what was accessed
Before changing settings, verify the scope of the incident.
Microsoft accounts can be used across email, cloud storage, identity sign-in, gaming, subscriptions, and synced Windows settings, so a breach may affect more than one service.
- Check for unknown sign-in alerts from Microsoft.
- Review recent sign-in activity on the Microsoft account security page.
- Look for sent messages, deleted mail, forwarding rules, or recovery email changes in Outlook.
- Check OneDrive for unusual file access, deletions, or sharing links.
- Inspect Xbox or Microsoft Store activity for unauthorized purchases.
If you see signs of persistence, assume the attacker may have created forwarding rules, added a recovery method, or copied authentication tokens from a trusted device.
Reset the password immediately
The first corrective action is a password reset.
If you can still sign in, change the password from the Microsoft account security settings.
If you cannot, use the official account recovery path to prove ownership and regain access.
- Choose a unique password that has never been used on any other account.
- Use at least 14 to 16 characters with a mix of words, numbers, and symbols.
- Avoid personal details, reused phrases, or password patterns.
Password managers such as Microsoft Authenticator, Bitwarden, 1Password, or Dashlane can generate and store stronger credentials than a human can reliably remember.
A unique password is critical because credential stuffing is one of the most common ways attackers re-enter accounts after a breach.
Remove the attacker’s access methods
Changing the password alone may not be enough if the attacker has already added recovery options or authorized devices.
Review every sign-in and recovery setting in the Microsoft account dashboard.
What to remove or replace
- Unknown recovery email addresses
- Phone numbers you do not recognize
- App passwords you did not create
- Trusted devices you no longer use
- Suspicious security info changes
If your account uses Microsoft Authenticator, verify that the device linked to the account is actually yours.
If a fraudster has enrolled a second method, remove it immediately and re-check the account a second time after a few hours.
Enable stronger multifactor authentication
Multifactor authentication, or MFA, is one of the most effective ways to protect a Microsoft account after compromise.
Microsoft supports several options, including authenticator prompts, SMS, email codes, and hardware security keys.
For the best balance of usability and security, prefer the Microsoft Authenticator app with number matching.
This makes it much harder for attackers to approve a sign-in through phishing or push fatigue attacks.
- Turn on MFA for the Microsoft account and any connected Microsoft 365 subscriptions.
- Use the Authenticator app instead of SMS when possible.
- Keep backup recovery codes in a secure offline location.
- Consider a FIDO2 security key for high-value accounts.
Organizations using Microsoft Entra ID and Microsoft 365 should enforce conditional access and MFA policies, especially for admin accounts and users with access to sensitive data.
Sign out of all sessions and revoke connected devices
After resetting the password and securing recovery methods, sign out of every active session.
This step helps invalidate cookies and tokens that may still be usable on the attacker’s browser or device.
In the Microsoft account security settings, choose the option to sign out everywhere if available.
Then review connected apps, devices, and mail clients that may still have authorization through OAuth or legacy authentication.
- Remove unknown Outlook, OneDrive, or Xbox app connections.
- Re-authenticate only devices and apps you trust.
- Check whether an email client is still syncing with old credentials.
This is especially important if you use the same account on Windows 10 or Windows 11, because a compromised device can silently reintroduce the threat.
Clean affected devices for malware or phishing access
A hacked account is often the symptom of a broader device or browser compromise.
If the attacker obtained your password through phishing, a malicious browser extension, remote access tool, or keylogger, the account can be stolen again immediately after recovery.
Run a full security scan using Microsoft Defender Antivirus or another trusted endpoint protection tool.
Update the operating system, browser, and all security software before re-entering passwords on the device.
- Remove suspicious browser extensions.
- Delete unknown remote access tools.
- Clear saved passwords from browsers you do not trust.
- Update Windows, macOS, Android, or iOS to the latest patches.
If the device still shows signs of compromise, back up essential files and perform a clean reinstall rather than continuing to use it for sensitive sign-ins.
Check Outlook, OneDrive, and billing for abuse
Attackers often use compromised Microsoft accounts to hide evidence, redirect mail, or make unauthorized purchases.
Review the services tied to the account and document anything suspicious.
Outlook and email checks
- Look for forwarding rules and inbox rules that send mail to unknown addresses.
- Check deleted items and sent items for messages you did not create.
- Review connected accounts and delegate access.
OneDrive and file-sharing checks
- Review recent files and sharing links.
- Remove public links that should not exist.
- Restore deleted or modified files from version history if needed.
Billing and subscription checks
- Inspect Microsoft Store purchases.
- Review Xbox purchases, game subscriptions, and gift card redemptions.
- Contact your bank or card issuer if fraudulent charges appear.
Document timestamps, suspicious IP addresses if provided, and any account changes.
This information helps with support escalation, charge disputes, and incident response.
Use Microsoft account recovery support when needed
If you cannot regain access through standard recovery, submit the official Microsoft account recovery form with accurate information.
Provide older passwords, contact details, device history, and any billing data that can help prove ownership.
Microsoft support is more effective when your submission is specific and consistent.
Avoid repeated guessing, because multiple failed attempts can slow the process or lock the recovery workflow.
For business environments, involve Microsoft 365 or Entra ID administrators immediately.
Admins may need to reset credentials, revoke tokens, check audit logs, or isolate compromised endpoints.
Strengthen the account after recovery
Once the account is back under your control, harden it so the same attack path cannot be reused.
The best post-breach defenses are small changes that close common gaps.
- Use a password manager and rotate all reused passwords on other sites.
- Turn on MFA for related email, banking, and cloud accounts.
- Review privacy settings and connected third-party apps.
- Enable sign-in alerts and keep recovery information current.
- Store backup codes in a secure place separate from your phone.
For higher-risk users, hardware security keys and phishing-resistant MFA are better than text-message codes.
This is especially useful if the Microsoft account is tied to a primary email address or business workflow.
Watch for follow-up attacks and social engineering
After a compromise, attackers may try password reset emails, fake support calls, or messages sent from the breached account to your contacts.
These follow-up attempts are designed to exploit trust while the incident is still fresh.
Warn close contacts if the account was used to send email or chat messages.
Tell them not to open unexpected links or attachments from your address until the account has been confirmed clean.
In the days after recovery, keep monitoring sign-ins, security alerts, and mailbox rules.
If you see any new unauthorized activity, repeat the containment steps immediately.