A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Hello,
Is the Xbox Network Device ID (
xbl.did) actually used by Microsoft Account/Xbox Support to verify ownership of a compromised account?
Yes. However, it is not a recovery key and does not establish ownership by itself.
If so, how can I determine whether the Gamertag and Device ID I provided were actually reviewed?
A Service Request does not show whether every item was reviewed or not.
I recommend replying in the same Service Request email thread to verify, but they usually respond just with scripts they have.
If the information did not match the account, I would like to understand what kind of mismatch could occur. The Device ID was obtained from a Windows PC that had previously been used with the compromised Microsoft account.
It's not only about the Device ID. If that's the form you're filling - https://account.live.com/acsr it does have many other questions.
Microsoft has already confirmed that unauthorized access occurred, so I am having difficulty understanding what additional ownership verification is possible when the attacker changed the security information and I can no longer access the account.
Confirmation of unauthorized access and verification of the person requesting recovery are two separate findings. Microsoft may be able to determine that an account was compromised from its activity history without being able to establish that the current claimant is the pre-compromise owner.
Your historical purchases are still valuable supporting evidence. Offer order numbers, dates, amounts, billing name and address, payment type, and only the last four card digits through the existing private Microsoft case channel. Do not post the full Device ID, billing details, or order information publicly.
Keep submitting new forms - you can do that twice per day.