Funzionalità di Microsoft 365 che consentono agli utenti di gestire le sottoscrizioni, le impostazioni dell'account e le informazioni di fatturazione.
#1 - Have described how to protect the email address that is the target which is not to allow it to be used as a login ID - can't add more to that. Trying to login using an email address that has been disabled as a login ID is not deemed as a login attempt. The described steps that you have taken are as much as you can do for an active account.
Let me put this another way. I have multiple Outlook.com accounts and not one ever gets any spam and I am serious when I use the word "never". I can't say the same thing for a couple of my non-Microsoft accounts but by the same token, I don't use my Outlook.com accounts to sign up for anything so these addresses never get "harvested".
#2 - Not having any recovery options on your account is almost a guarantee to not being able to being to recover an account should that become necessary. As for someone who gains access to your account seeing your recovery email addresses, each email account should be protected accordingly. The hacker would still need to know the password to the account in order to access it. If someone uses the same password everywhere, then yes, it's a dangerous scenario but one of their own making. So many people wonder how their social media accounts get hacked so easily when they use the same email address / password combination on all their accounts.
@3 - microaoftoneline.com -for business accounts