Password security guide
Microsoft Account Password Requirements and Security
Use a unique generated password or a Microsoft-supported passkey, then configure more than one safe recovery and verification method.
Check the current Microsoft password policy
Microsoft personal, work and school accounts can have different policies, and an organization may impose additional rules through Entra ID. Use the current account creation or password-change interface as the authoritative validator rather than an old list of minimums.
For a personal account that still uses a password, start with a long random value and store it in a manager.
Microsoft account passkeys
Microsoft supports passkeys for personal accounts and for work or school accounts when the organization permits them. A passkey can be stored in a password manager, phone, tablet, hardware security key or Windows device using Windows Hello, depending on the flow.
Turn on two-step verification
Two-step verification requires an additional proof when signing in. Microsoft recommends maintaining multiple pieces of security information because losing the only verification route can delay or prevent recovery. Microsoft has announced a move away from SMS for personal-account authentication and recovery, so review the current available methods.
Personal versus work or school accounts
An employer or school controls which methods are available, conditional-access rules and recovery. Follow the organization policy and contact its administrator for lost access. Do not register business credentials in an unmanaged personal sharing workflow.
Review security information and sessions
Keep recovery email, authenticator registration and passkeys current. Remove old methods only after testing replacements. Review recent sign-in activity and investigate unfamiliar locations, devices or approvals.
Compromise response
Use Microsoft account security from a trusted address, change the password if one remains, review sign-in methods and aliases, revoke unfamiliar access, and replace reuse elsewhere. For a work account, notify the administrator because tokens and organizational resources may require central revocation.