Why is account recovery impossible when TSV is enabled?

Oliver 5 Reputation points
2026-09-06T18:32:18.61+00:00

I feel like, if account safety is important to Microsoft, there would be some way to recover accounts that have two step verification enabled. It seems like a massive oversight, maybe I’m crazy but people have connections to these accounts that include thousands of hours of work, game licenses, verification of other accounts, etc.

It just doesn’t make me feel safe that my account got locked and I have since lost complete access to it forever because I was trying to keep it more safe by enabling two step verification. In the future it just would feel bad to enable it at all, even though it’s considered safer for daily use.

Imagine a prison where the inmates are kept under close supervision and the goal is prison security, one person is found deviating from security protocol, whether they meant to or not, and they are put in solitary confinement FOREVER. The difference between a Microsoft account and a human is blatant but the idea isn’t that far fetched. Microsoft accounts do have value beyond just information storage.

I would like to know your thoughts, and hopefully I can get my account reinstated even though it will be “permanently suspended” because I made some obscure mistake that I don’t even know I made.

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Oldest
  1. Rob Koch 26,070 Reputation points Volunteer Moderator
    2026-09-06T21:25:22.3766667+00:00

    It's not impossible, you just have to have at least 2 alternate methods of verification available even if some of these are lost, which in most cases means at least 3 and better off 4 or more optional methods when available.

    As a past network administrator and security professional, this is obvious to me, but unfortunately something that many consumers simply don't seem to get, regardless of the fact that Microsoft typically prompts them to add more verification methods whenever they get the chance.

    I personally have the Microsoft account password which I won't remove until Microsoft realizes the precise issue you're bringing up here, the legacy SMS phone option that's currently in process of being dropped, a secondary Gmail used only for verification and not stupidly synced as the Microsoft account name that's just asking for trouble like account theft or loss since then it's not useable as an alternate method (the Microsoft account is legacy MSN domain), Microsoft Authenticator backed up to the Google cloud for recovery, Windows Hello Face (camera) and PIN on a Microsoft Surface Go tablet which also uses a Passkey for background login to the account (both that device and another without a camera are registered as trusted devices in the account), and lastly a Microsoft account Recovery key which may not be useable since it's not actually listed among the verification methods, but really should be since it acts as a form of identity that supposedly only the account owner should know.

    The chances I wouldn't have at least 2 of the above verification methods available is unlikely, at least once I'm home if the house hasn't been destroyed with all of my devices including the phone contained inside it. But that's why the Recovery Key should still be useable as a verification backup if it isn't. since not everyone has the smartphone or other hardware available for things like Windows Hello, and it's something you could print out and store offsite in a safe deposit box for example.

    Unfortunately, many people are learning these technical issues with account security and verification methods the hard way, which hopefully they'll use as a learning experience to be better prepared in case something catastrophic happens to them in the future.

    Another option you might consider for the future is a combination of a Passkey with Passwordless account option, since though that removes the password as a verification method entirely, it only leaves less easily phished or otherwise stolen methods, while moving ahead with the generally safer Passkey method that Microsoft and other vendors are supporting since it's phishing resistant. It also would remove the risk that you lose the account due to 2FA.

    Rob

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.