I have received an email requesting I provide a new password or else in 24 hours my account will be deactivated

Janice Ayers 20 Reputation points
2026-04-21T16:53:25.79+00:00

Received 2 emails that looked suspicious last week asking me to sign HR documents for Microsoft, I reported them as spam. I received an email (all three have been addressed "note to self") this time wanting me to go in and change my password. My outside IT vendor set up my account with Microsoft. This was approximately 2 years ago. I am current with all payments. The email received today explains that I need to change password or my account will be deactivated. I went into my Microsoft account, and it listed that there were no issues to address.

I feel that this is just another attempt to hack into my system. I would like to know if my account has anything pending.

Outlook | Web | Outlook.com | Account management, security, and privacy
0 comments No comments

Answer accepted by question author
EmilyS726 265.1K Reputation points Independent Advisor
2026-04-21T17:26:25.0966667+00:00

This is 100% phishing scam. Microsoft doesn't deactivate account due to password not changed within xx hours.

A legitimate email from Microsoft regarding your account always comes from domains ending in @accountprotection.microsoft.com

Was this answer helpful?

6 people found this answer helpful.
0 comments No comments

1 additional answer

Sort by: Most helpful
  1. AI answer

    2026-04-21T16:53:39.4133333+00:00

    The message described is almost certainly a phishing/scam attempt, not a legitimate Microsoft requirement to change the password.

    To verify and protect the account:

    1. Check if the email is really from Microsoft
      • Legitimate Microsoft account security emails come from domains such as @accountprotection.microsoft.com, for example ******@accountprotection.microsoft.com.
      • If the sender is anything else (misspellings, extra words, or non-Microsoft domains), treat it as phishing.
      • Do not click any links or open attachments in the suspicious emails.
    2. Check recent sign-in activity
      • Go directly (using a browser, not email links) to the Security basics page and sign in.
      • Open the Recent activity page to see sign-ins for the last 30 days. If there is activity that is not recognized, expand it and follow the prompts to report This wasn't me or Secure your account as described in the guidance.
    3. If anything looks suspicious on the account
      • From the Security basics or Security settings pages, immediately change the password to a strong, unique one and update security info (phone, alternate email, Authenticator, etc.).
      • Follow the steps in the “If someone has accessed your account” and “How to recover a hacked or compromised Microsoft account” guidance if there are signs of compromise.
    4. If the account page shows no issues
      • If the Microsoft account dashboard and Security basics pages show no alerts or required actions, and the only warning is coming from the email, then the email can be treated as phishing and ignored/deleted.
    5. Handling phishing in Outlook/Outlook.com
      • In Outlook/Outlook.com, mark such messages as junk or phishing so they are filtered in the future, as described in the phishing guidance for Outlook.

    The account itself does not get deactivated simply because of a random email; any real required security action will also appear when signing in directly to the Microsoft account and security pages, not only in an email.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

    1 person found this answer helpful.

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.