Hello,
Bottom line is - this email is fake, it is spam and scam. And your account is not in any sort of danger. So there's no need to step 3 other than common sense security practice.
A leigitimate email from Microsoft regarding your account always comes from domains ending in @accountprotection.microsoft.com. If there's any update you need to know about your account, you don't need to go look for it else where, it will be communicated with you via the legitimate Microsoft email address.
For step 2, you did the right thing, but it doesn't mean they will stop coming in. This round of scam is all using aol.com address as it appears, and they can come in different aol.com address, if you block one, doesn't mean it will block another email address if the username is different. As for the content, it will take time for Microsoft to learn over time via reports.