issue withRegistering MFA

BENERJEE KOTA 1 Reputation point
2022-10-04T15:38:33.837+00:00

Hello All,

External user having Guest account in the Tenant has lost her Phone. We have tried to revoke/requires re-registering MFA. but still it is routing the request old phone where authenticator app was configured. I have deleted the guest account and re-sent the invite. She accepted the invite but still the request is going to old phone. We have tried in incognito browser and Edge browser but the issue is same.

Can you please advise how can we resolve the issue.

Thank you.

Regards,
Ben,

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Michael Smith 2,931 Reputation points Microsoft Employee Moderator
    2022-10-04T15:59:58.977+00:00

    Hi Ben,

    The verification number for the user is under the authentication methods of the user profile.

    Can you ensure the correct number is entered here and please click "Require re-register multifactor authentication"

    247443-image.png

    0 comments No comments

  2. Dillon Silzer 60,726 Reputation points Volunteer Moderator
    2022-10-04T16:01:59.477+00:00

    Hi @BENERJEE KOTA

    Try resetting her contact methods through the MFA Dashboard:

    1) Go to https://account.activedirectory.windowsazure.com/UserManagement/MultifactorVerification.aspx?BrandContextID=O365#

    2) Search the name with the magnifying glass

    3) Double click the name

    4) On the right hand side hit Manage user settings

    247444-image.png

    5) Check off Require selected users to provide contact methods again.

    247415-image.png

    6) Press Save

    Have the guest sign out and sign back in and they should be presented with the screen to add a different phone number.


    If this is helpful please accept answer.


  3. JamesTran-MSFT 37,226 Reputation points Microsoft Employee Moderator
    2022-10-06T21:24:40.117+00:00

    @BENERJEE KOTA
    Thank you for your post!

    Since the external user that you're inviting to your tenant lost their phone, and the MFA requests are still going to their old number/authenticator app, you'll have to update or add an Alternate Mobile number to their Authentication methods via their profile within Azure AD.

    248291-image.png

    Once you've added the Alternate Mobile number, when the user is logging in, they'll have to select the alternate number when performing MFA.
    248301-image.png

    I hope this helps!

    If you have any other questions, please let me know.
    Thank you for your time and patience throughout this issue.

    ----------

    Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.