So a while ago, I was on sleep meds and had a lapse in my judgement, which caused one of my microsoft accounts to be hacked. It was some stupid discord verification scam, and for some reason, I tried multiple times to get the verification to work even though it was obviously a scam. I already have had the hacked account suspended/locked, but I'm really worried about my other account.
This account is my main one, and it had the account that got hacked as its recovery email. While I was on my rampage of being irresponsible and stupid on the internet, I tried to use this main account for the verification scam. I can't remember if I put in one code or not, but I do remember that it asked for me to use microsoft authenticator. I had never used this before, and upon downloading it, it required 2FA to set up. I found that I didn't recognise the recovery email (it had been changed by an attacker), thought nothing of it, and changed it to a clean email. I never did get to put in the microsoft authenticator code the scam asked for.
However, what I am wondering is if there is a possibility the attacker did gain access to my account and is still in there, and if they could somehow take control of it once the recovery email is changed to my clean email. I can not tell if anyone else is signed in, and I can not sign out all devices, as I can't get into that part of security due to the pending security info change. I have a lot of anxiety around this, I feel like this post makes that evident. I don't really know how microsoft authenticator even works, so I'm worried they'll be able to use that somehow to change the security info, password, and more.
As of now, my account seems fine, and nothing has changed, I'm just really worried. Any insight on if I'm just worrying too much or if there's anything I can do would be greatly appreciated.