A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Subject: Security info replacement completed but completion links appear expired / risk of repeated 30-day waiting period
Hello,
I need guidance on the safest official process for completing Microsoft account security-info replacement after the 30-day waiting period has already ended.
I have several personal Microsoft accounts affected by old two-step verification / security-info problems. I have access to the recovery/contact Gmail accounts that received Microsoft’s security-info replacement emails.
I also have screenshots showing that the affected accounts are associated with my active Microsoft 365 subscription / sharing environment. The screenshots show:
- My active Microsoft account subscription page.
- Microsoft 365 subscription management.
- Recurring billing and active subscription details.
- A list of shared / associated accounts under the Microsoft 365 subscription area.
- The affected account pattern includes the same family of account names, including accounts corresponding to body1, body3, body4, body5 and body**6.
- The account names shown in the Microsoft account/subscription area align with my account naming pattern and the affected recovery emails.
Separately, I have official Microsoft account team emails for the affected accounts. These emails have the heading “Security info replacement” and state:
“Good news! The waiting period is over. You can now replace all your security info and change the password…”
The emails include a “Replace security info” button.
The affected masked accounts shown in the emails include:
- bo********@hotmail.com
- bo********@hotmail.com
- bo********@hotmail.com
There are two different scenarios:
Scenario 1: bo**********@hotmail.com and bo**********@hotmail.com
- The 30-day waiting period appears to have completed.
- Microsoft sent the “Good news! The waiting period is over” security-info replacement emails.
- I have not clicked through or retriggered the recovery flow for these two accounts.
- The completion links may now be expired.
- I want to know the safe official way to complete the already-approved security-info replacement without accidentally restarting the 30-day waiting period.
Scenario 2: bo********@hotmail.com
- The 30-day waiting period also completed.
- Microsoft sent the “Good news! The waiting period is over” security-info replacement email.
- When I later tried to use the completion link, it appeared to be expired or no longer valid. (which is why I presume the other links are expired...)
- The process appeared to route back into the normal sign-in / security recovery flow.
- This appears to have triggered a second 30-day waiting period.
- I want guidance on how to resolve this without causing another restart of the waiting period.
I am not asking Microsoft Support to bypass security, send a password reset link, or manually change account details. I understand that support may be limited in what it can alter directly.
I am asking for official process guidance on these specific questions:
If Microsoft sent a “Security info replacement” completion email after the 30-day waiting period, but the “Replace security info” link is now expired, what is the correct official process to complete the already-approved security-info replacement?
For bo********@hotmail.com and bo********@hotmail.com, should I avoid clicking the old completion links until Microsoft confirms the correct process?
Is there any official way to refresh, reissue or continue from an expired completion link without restarting the 30-day waiting period?
For bo********@hotmail.com, where an expired completion link appears to have caused a second 30-day wait, is there a support path to review the case and prevent repeated waiting-period loops?
What evidence should I provide? I can provide:
- screenshots of the Microsoft 365 subscription / sharing page showing the affected accounts associated with my subscription environment;
- screenshots of the Microsoft account team “Security info replacement” emails;
- screenshots showing the affected masked accounts;
- the recovery/contact email addresses used;
- the dates and wording of the Microsoft emails;
- the expired-link / second-waiting-period evidence for bo********@hotmail.com.
- the dates and wording of the Microsoft emails;
- the recovery/contact email addresses used;
- screenshots showing the affected masked accounts;
- screenshots of the Microsoft account team “Security info replacement” emails;
Please advise the safest official next step before I click any old recovery/completion links or attempt another sign-in recovery flow. - Note - these are all 2-step verification accounts, which is what caused me the problem in the first place.
Thank you.