← everything

Locked out of the account your computer signs in with

2026-08-07 · Account lockout

Most account lockouts take away a service. This one can take away the computer.

When a Microsoft account is also the sign-in for the device, the licence for the software on it, the destination for the device encryption recovery key, and the mailbox where every recovery notice is sent, a single lockout reaches into hardware you physically own and standing in front of it does not help.

That is the thing worth understanding, and the thing worth defusing in advance.

Do these before you need them

Ten minutes, and they are what makes the difference between an inconvenience and a catastrophe.

  • Save your device encryption recovery key somewhere off the account. If it is only stored in the account you are locked out of, and the device asks for it after an update or a hardware change, the data is gone. Print it. This is the single most damaging thing on the list and it is invisible until the day it is not.
  • Create a local administrator account on the machine. Not to use daily — so a working login exists that no remote decision can revoke.
  • Add a recovery email at a different provider on a different domain. A second address in the same account system is not a second address.
  • Print your backup codes. Paper, not the cloud drive attached to the account.
  • Export your mail. Whatever client you like, however dull. An offline copy is the entire difference between losing access and losing correspondence.
  • Write down which licences depend on this account — the OS, the office suite, anything with a subscription — so you know what is at stake and what needs a separate route.

If it has already happened

Work out which of the three it is. They present similarly and the remedies do not overlap:

SymptomWhat it is
Password rejected, recovery flow offeredCredential problem — recovery applies
"This account has been locked" after odd activitySecurity hold — usually the most recoverable
"Account closed / suspended" citing termsEnforcement — recovery flow will not touch it

Use the recovery form from a device and network the account recognises. The form weights familiar signals. Filing from a new machine on a strange network is the weakest possible position. Use the computer you always used, at home.

Answer with what you actually used. Old passwords you genuinely had. Approximate dates. Subject lines of mail you actually sent. Real-but-imprecise beats precise-but-reconstructed.

Space out attempts and change something between them. Ten failed submissions in an hour is worse than two on different days from different known devices.

Deal with the machine separately and in parallel. Local account, local data, recovery key. Whether the machine is usable is a different problem from whether the account comes back, and it is frequently the more urgent one.

The circular part

The recurring trap, and it is worth stating in full because it catches everybody:

  1. The account is locked.
  2. Notices about the lock go to the mailbox on that account.
  3. The recovery route wants a code sent to that mailbox.
  4. The device that would receive it wants the account to sign in.

Every door out is behind the door that is shut. This is the same structural failure that runs through nearly every story on these sites: the notification channel depends on the thing being notified about.

The fix is entirely preventative, and it is one sentence: the address that receives your recovery notices must not be provided by the company you might need to recover from.

To be fair

Account compromise is real, and a device sign-in bound to an account is what lets a stolen laptop be useless to a thief and lets a replacement machine come back with everything on it. Those are genuine goods and lots of people benefit from them without ever thinking about it. A recovery process that trusted anyone who asked would be an attack.

The complaints are narrower:

  • The bundling was never presented as a risk. Convenience was the pitch. The fact that one enforcement decision could take mail, licence, device and encrypted data together was not part of it.
  • The recovery key default sends the last resort into the account it protects. That default is indefensible, and it is on by default.
  • There is no human, at any price. No tier exists that buys a person for account recovery, and people would pay for one.

Keep a local account, keep your recovery key on paper, and keep one mailbox that belongs to nobody but you. Own your recovery, or you do not own your machine.

Post your story