About this tool
Weighted 15-step checklist for Microsoft account two-step verification, recovery code, passwordless sign-in, session cleanup and Outlook rule checks.
This guide is a weighted, 15-control checklist for a Microsoft account: two-step verification, the single recovery code, verified alternate contact details, Authenticator approvals, session and app-password cleanup, and the Outlook forwarding check that catches an intruder who is still reading your mail. One Microsoft account typically holds Outlook, OneDrive, Windows sign-in and Xbox purchases together, so the controls are scored by how much of that a takeover would reach. Four are marked critical and the score is capped at 69% until all four are done.
Open Microsoft Account 2FA Guide on AltFTool — it loads instantly in your browser.
Add your input to the workspace.
Adjust the options until the result looks right.
Copy or download the output and put it to work.
Mail forwarding rules and app passwords survive a password change, so both are on the list rather than assumed clean.
Controls are weighted by how much of your mail, files and payment methods each one protects.
The checklist runs in your browser and never asks for your Microsoft account, password, recovery code or an approval.
Sign in at account.microsoft.com, open Security, choose Advanced security options, then turn on Two-step verification and follow the prompts. Set up the Microsoft Authenticator app during that flow rather than relying on SMS, and save the recovery code the same page offers.
One. Microsoft issues a single 25-character recovery code from Advanced security options, and generating a fresh code immediately invalidates the previous one. Print it or store it in a password manager, because it is the route back in when you have lost both your phone and your alternate email.
Yes. Advanced security options has a passwordless account setting that removes the password entirely, after which you sign in with the Authenticator app, Windows Hello, a security key or a code sent to your verified contact details. It removes the one credential that can be phished or reused elsewhere.
Changes that reduce your recovery options can take up to 30 days to take effect. The delay is deliberate: if someone else gets into the account, it stops them stripping out your phone number and alternate email before you have a chance to notice and react.