Managing security settings and protections in Outlook on the web for business
Frequent lockouts usually mean repeated sign-in failures or background apps repeatedly trying old credentials. For a legacy/shared mailbox being monitored, use these steps to stabilize access and improve security:
- Stop the repeated bad sign-ins
- Make sure no one is using old or incorrect passwords for that mailbox on any device (PCs, phones, tablets, shared computers, old Outlook profiles, mobile mail apps, printers, scanners, etc.).
- Remove the old mailbox profile from any classic Outlook or mobile mail apps where it might still be configured.
- If classic Outlook keeps prompting for a password, verify the username is the full email address and that the password is current. If the password was changed recently, update it in Outlook so it does not keep sending the old one.
- Change the password and secure the account
- Change the password for the old mailbox to a strong, unique one that only the current employee (and IT/admins) know.
- Set up two-factor authentication (2FA) on the account if available in the tenant. This reduces the chance of external attackers causing lockouts.
- Use safer access patterns for the legacy mailbox
- Instead of having the employee sign in directly as the old user, configure the old mailbox as a shared mailbox (if using Microsoft 365) and grant the employee Full Access/Send As permissions. Then the employee signs in only with their own account and opens the old mailbox as an additional mailbox.
- This avoids separate credentials and reduces lockout risk.
- Reduce exposure of the old sign-in identity
- If this is a consumer Microsoft account (Outlook.com), consider adding a new alias and making it the primary sign-in, then disabling sign-in with the old alias so it can still receive mail but cannot be used to log in. This helps prevent attackers from repeatedly trying to sign in with the old address.
- Plan the migration and decommissioning
- Complete the move of all important correspondence from the old mailbox to the employee’s own mailbox (or to a shared mailbox).
- Once all required data is moved and retention requirements are met, stop using the old mailbox for interactive sign-in and, if appropriate, disable it or keep it only as an archive/shared mailbox.
If the account is a personal Microsoft account (Outlook.com) and is being locked due to suspicious activity, use the “Unblock my Outlook.com account” and “Request for Account Reinstatement” options described in the referenced guidance, and avoid repeated sign-in attempts for at least 24 hours after a lockout.
References: