A tool for managing user identities, credentials, and access across on-premises and cloud environments
Hugo C,
From the standpoint of those like yourself posting here, I fully understand your confusion, since the only way I've found as a longtime helper on these and previous Microsoft forums to determine the convoluted set of policies which created the current nightmare for both Microsoft's customers and the true Microsoft Support personnel, is by working backwards through the policy changes and the mess of support issues and posts it has caused here.
The most official page I can find relating to this is generally appropriate, but simply not as utterly clear as it should be, with the following notes that they instead seem to feel are enough but lack the clear statement that many accounts will be unrecoverable, leaving the customer and any support agents they may try to reach spooling endlessly until the eventual conclusion most will reach of that simple fact.
Important
- If you have turned on two-step verification and cannot access any of the alternate methods to get a verification, we cannot help you, sorry. To protect your account and its contents, our support agents are not allowed to send password reset links, or access and change account details.
- If you have not turned on two-step verification and don't recognize any of the verification email or phone options when trying to reset your password, use the Sign-in Helper tool.
Note that the first paragraph above is clear about the situation when two-step verification (2FA) was enabled, but isn't clear about the more common situation when all security information has been changed including the possibility that the malicious attacker (account thief) has also added their own 2FA, which typically isn't reversible by the original account owner, since the fact that the original account alias (email address) has been changed, as well as any other verification email or phone numbers, inherently means that the account is now unrecoverable.
Supposedly the Sign-in Helper Tool mentioned in the second paragraph above is supposed to allow the original account owner to reverse all of the changes made by the attacker, but from what I've seen this often doesn't work, which I can only assume is either the result of too much time having passed or some other specific change the attackers have learned that makes this recovery method impossible.
However, I don't believe you can blame the first level Support agents for this confusion either, since as you appear to have guessed, they don't seem to understand these specific facts including the most critical one that even the once more capable back-end (you call them high-level) account personnel are now apparently only able to block one of these heavily modified accounts, since not even they can reverse the critical security changes that are causing the true account lockout.
Note my bolding and italics in the portion of the first paragraph above that states this fact, though it doesn't clarify what that actually means in relation to the added issue of the modified security verification items.
So yes, your rant is basically justified, but the problem here is actually deeper than you suspect, since the fact that the first level support agents will be evaluated not only on closing the case, but also any negative comments you might make if they told you the utter truth, which unfortunately many customers will unknowingly take out on the agent in their follow-up survey, means that the agents have learned how to try to pass on the problem to someone else.
Do you now see the true combination of issues causing the confusion and why it has become a much larger problem than it really should be, simply because someone inside Microsoft has chosen not to be utterly clear about which situations can truly be recovered and which never can be?
Rob
< EDIT > To be clear, the reason that Microsoft has switched to using both AI responses and forms for account recovery is that human Support agents can be either tricked, coerced or simply make mistakes while making the changes necessary to recover an account, so making the customer do this process themselves was actually the better choice.
It's really the fact that the potential for successful recovery isn't clear combined with the radical changes to an automated process that many customers are used to assuming they can let someone else in Microsoft Support do for them that's amplified the problem, while the human support option has actually seen reduced availability for decades now, it's just the first time in many years that most customers may have tried to reach human support that's contributing to the surprise.