MFA push notifications

Bernard Lai 1 Reputation point
2023-11-20T01:31:02.98+00:00

Hi, currently we’ve a user whereby the old phone were damage and can’t access anymore and had requested for a reset of MFA, we’ve tried revoke all the MFA session and re-register the MFA, after the re-register however when he login to portal.azure, the MFA push notifications still goes to his old device, how can we remove that and change to the new phone? The per-user MFA were disabled, need advice on this, thanks.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
Microsoft Security | Microsoft Authenticator
{count} votes

1 answer

Sort by: Most helpful
  1. Gudivada Adi Navya Sri 21,080 Reputation points Moderator
    2023-11-20T04:08:50.6066667+00:00

    Hi@Bernard Lai

    Thank you for posting this in Microsoft Q&A.

    As I understand that one of the user phone where damage can’t access anymore and had requested for a reset of MFA.

    Option1: After the re-register user need to set up their MFA just like a new user.

    Follow below steps to reset MFA.

    1. Sign into the Microsoft Entra admin center as a global administrator
    2. Browse to Identity > Users > All users > Select user.
    3. Select Authentication methods.
    4. Click "Switch to the new user authentication methods experience".
    5. Highlight the usable method associated to the redundant device and delete it.
    6. Select Require re-register MFA, Click Yes, reset it to reset the user's MFA.

    The next time the user logs in, they will need to set up their MFA just like a new user.

    For your reference https://learn.microsoft.com/en-us/entra/identity/authentication/howto-mfa-userdevicesettings#manage-user-authentication-options

    Option2: Use a Temporary Access Pass create temporary Access Pass for that user ask them to login with Temporary Access Pass. A Temporary Access Pass is a time-limited passcode that user can use to sign in to your M365 account without old device. Once user logged in to portal. He himself can register for a new device and can delete the old device as well.

    option3: Also, if user has backup of authenticate app settings refer to this link on how to restore it - https://support.microsoft.com/en-gb/account-billing/back-up-and-recover-account-credentials-in-the-authenticator-app-bb939936-7a8d-4e88-bc43-49bc1a700a40

    Hope this helps. Do let us know if you any further queries.

    Thanks,

    Navya.

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.