How to properly protect your account

Martin Brinkmann
Jan 8, 2015
Updated • Jan 8, 2015

If you are using Microsoft's email service you have various options to connect to it. You can use the web interface, mobile apps or desktop email clients.

Regardless of how you use the service, you may want to make sure that it is properly protected against hacks and other malicious attacks. accounts are directly linked to Microsoft Accounts. This shows when you try to locate security related settings on the Outlook website as you will notice quickly that there are none.

All security and the majority of privacy related features and settings are accessed on the Microsoft Account website instead.

You can use the link posted above to get there which is the fastest option to access it. The Security & Privacy overview page lists important preferences that allow you to modify these account-related settings.

microsoft security privacy

Lets take a look at the most important options on the page:

1. Change password

change password


It is highly recommended to select a secure password. There is no catch-all definition for secure though but generally speaking, the more characters the password has the better.

Microsoft's requirements are that the password needs to be at least 8 characters. If you want to improve security, I suggest you use at least twice the number using a mix of letters, numbers, upper and lower-case characters and special characters.

2. Monitor activity

microsoft account activity


This page lists the last sign-ins on a single page. Information such as the location of the device the sign in was recorded from, date and time, IP address or platform are listed for each sign-in attempt regardless of whether it has been successful or not.

3. App permissions

app permissions


Here you find apps and services that you have given permissions to. This includes Windows apps and may also include Web services and mobile applications.

Each app and service is listed with its name and the data you last used it. A click on the edit button allows you to remove permissions again.

4. Advanced Security features


You find additional, some would call it the most important - security settings and features on this page It lists all email addresses and phone numbers associated with the account, and offers options to remove them or add new ones.

security alerts

This is important for a number of reasons. First, you want to make sure that old accounts and numbers get removed immediately from the account as others may use them to gain access to your account.

Second, if you plan to enable two-step verification, you may need to add a phone number in case you have not already.

Last but not least, it is also possible to define alerts for each account and phone number. Microsoft will notify you if the company believes there is a problem with the account security-wise. Note that it is not possible to opt-out of receiving alerts for the primary account.

Sign-in preferences allow you to select the email addresses that you can sign-in with. While you cannot modify the preference for the main account, you can enable or disable all other accounts on this page.

Two-step verification on the other hand improves the login process by adding a second verifier to it. Instead of signing in just with the username and password, you are asked to supply a code that is sent to your email address or mobile phone. This is probably the best option to improve account security.

Identify verification apps can be used configured to generate that code locally.

App passwords come into play once you have configured two-step verification. Since some programs and devices don't support it, you need to create so-called app passwords for them that allow you to sign in without using the verification codes.

Recovery Code on the other hand comes in handy if you need to restore access to your account. It can be used for that purpose and should be kept in a safe location because of it.


This is a quick list of recommendations to secure your / Microsoft account.

  1. Pick a secure password that is at least 16 characters long and uses upper- and lower-case characters, numbers and special characters.
  2. Enable two-step verification for the account.
  3. Create a recovery code and safe it in a secure location.
  4. Review account activity and app permissions regularly.
How to properly protect your account
Article Name
How to properly protect your account
Find out how to properly protect your account to improve its security and make it harder for malicious attackers to gain access to to it.

Previous Post: «
Next Post: «


  1. hessam said on February 26, 2016 at 4:26 pm

    it seems Microsoft removed 16 characters password limitation.i changed my password to o around 25 characters
    but not tested for 100 characters

  2. hessam said on January 8, 2015 at 2:42 pm

    dont allow me select longer than 16 characters
    Your password can’t be longer than 16 characters.

    1. Martin Brinkmann said on January 8, 2015 at 2:52 pm

      I have modified the recommendation to 16 characters. Wonder why they limit it to that.

      1. Decent60 said on January 8, 2015 at 8:36 pm

        It was was made a big fuss about 2 years ago when took over. “Explanation” is here:

        And to Quote another site that “quoted” Microsoft (they didn’t supply a source link):

        Please note our research has shown uniqueness is more important than length and (like all major account systems) we see criminals attempt to victimize our customers in various ways; however, while we agree that in general longer is better, we’ve found the vast majority of attacks are through phishing, malware infected machines and the reuse of passwords on third-party sites – none of which are helped by very long passwords. Sixteen characters has been the limit for years now. We will always prioritize the protection needs of users’ accounts and we will continue to monitor the new ways hijackers and spammers attempt to compromise accounts, and we design innovative features based on this. At this time, we encourage customers to frequently reset their Microsoft account passwords and use unique passwords that are different from other services.

      2. Martin Brinkmann said on January 8, 2015 at 9:01 pm

        I don’t think that makes a whole lot of sense considering that it should be the user’s decision and not Microsoft’s to artificially limit the password length. Thanks for digging up the explanation!

      3. hessam said on January 8, 2015 at 3:10 pm

        i remember hotmail (now outlook) 1 year or 2 year ago even allow 100 characters for password
        but after sometime they removed this feature and limited it.

        i use roboform password generator and it show me 16 characters= 95 bit strength
        i think it is not Enough and this is not good

Leave a Reply

Check the box to consent to your data being stored in line with the guidelines set out in our privacy policy

We love comments and welcome thoughtful and civilized discussion. Rudeness and personal attacks will not be tolerated. Please stay on-topic.
Please note that your comment may not appear immediately after you post it.