Share via

How to set 2FA

Enqi Lam 0 Reputation points
2026-05-03T15:07:54.91+00:00

My account has been hacked and it is displaying weird bot in every mail in my inbox (meaning I can’t view the content of my email, all email shows the same content by the bot). I’ve reset my password and am trying to set up 2 FA, however outlook prompt me to use OTP with my mobile but it lead me to a page that shows the method is not available, when I try to key in using my new password it says I’ve been trying to sign in with the wrong password and it didn’t allow me to set up the 2Fa Even tho I’m already logged in to my outlook.

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-05-03T15:08:14.9433333+00:00

    Follow these steps in order, since the account is already compromised and 2FA setup is failing:

    1. Scan all devices for malware before doing anything else
      Use an up-to-date antivirus and run a full scan on every device used to access this account (PC, phone, tablet). If using Windows 8.1 or Windows 10/11, turn on and run Windows Defender as described in the guidance for recovering a hacked account. Do this before changing passwords again.
    2. Change the Microsoft account password again (from a clean device)
      After scans complete, go to the Microsoft account page and change the password from a device that is clean. Use a strong, unique password as recommended in the hacked-account recovery steps. If sign-in fails, use the reset your password flow instead.
    3. Check for signs the attacker is still in the account
      Once signed in:
      • Review connected accounts, forwarding, and automatic replies to remove anything unfamiliar (attackers often add forwarding or rules to keep control).
      • If Outlook Web is accessible, check Settings → Mail → Rules and Forwarding for any suspicious rules and delete them.
    4. Try to set up MFA using available methods
      Since SMS OTP is failing with “method not available,” use whatever method the account security page offers:
      • If prompted with Help us protect your account, select Next.
      • Install the Microsoft Authenticator app from the official store or from the Authenticator app page.
      • Follow the steps: choose phone/text first if it works, then scan the QR code with Authenticator and approve the notification as described in the Microsoft 365 MFA setup article.
      If SMS truly cannot be used, look for options like adding Authenticator directly or another email/phone as security info.
    5. If 2FA prompts or passwords keep failing, use the official recovery and support paths
      If the system keeps saying the password is wrong or blocks 2FA setup even though already signed in, treat it as a still-compromised or unstable state:
      • Use the Sign-in Helper or account recovery flows referenced in the hacked-account article to verify identity and regain stable access.
      • If the account appears hacked or locked, follow the full guidance in How to recover a hacked or compromised Microsoft account, including checking/resetting security info.
    6. After regaining stable access and MFA
      • Confirm all security info (phone, alternate email, Authenticator) belongs to the account owner only. Remove anything unfamiliar.
      • Keep MFA enabled and monitor sign-in activity for unusual prompts. Deny any sign-in prompts that were not initiated.

    If at any point sign-in or 2FA setup cannot be completed, continue with the hacked-account recovery steps and use the support/contact options they provide, as manual support cannot bypass the automated security checks but can help when the automated flows error.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

    1 person found this answer helpful.

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.