Passwordless: Unregister a device so that it can be used in another tenant

Phillip Baker 46 Reputation points
2021-03-25T12:50:11.993+00:00

It is a pre-requisite for passwordless that a device 'be registered' with 'the organization' which presumably means it is added to the user's profile / directly to Azure AD somewhere.

It was not clear from the messaging in the setup flow on Authenticator iOS that it is not currently supported to use passwordless with more than one Microsoft tenant even though this is a constraint that gave rise to a feature request in 2018.

The device is now registered with a tenant, but - having discovered that I can only have it registered to one tenant - not the one I would choose.

I have 'deactivated' phone authentication in the Authenticator app for the tenant it was activated against, but the device still seems to show as already registered with that tenant - if I go into enable phone authentication for the tenant I want it enabled on, it tells me it's already registered elsewhere, and if I go to enable it on the tenant I no longer want it on, there is already a green check mark next to the requirement to register the device.

I can find no documentation explaining where/how these devices are 'registered'. I did notice that the iPhone was showing in AAD devices and have tried deleting the entire device from Azure AD already, to no effect.

Is it just a matter of waiting for the deactivation/deletion to take effect, or are 'passwordless devices' managed somewhere else?

Microsoft Security Microsoft Entra Microsoft Entra ID
Microsoft Security Microsoft Authenticator
0 comments No comments
{count} vote

Accepted answer
  1. Svante Hugh 91 Reputation points
    2021-06-19T01:00:01.253+00:00

    To unregister the device,
    Open Authenticator app -> hamburger menu -> Settings -> Device Registration -> Unregister device

    3 people found this answer helpful.

2 additional answers

Sort by: Most helpful
  1. VipulSparsh-MSFT 16,311 Reputation points Microsoft Employee
    2021-03-26T07:53:04.07+00:00

    @Phillip Baker It should be a matter of waiting for deactivation as if you remove/delete the device from azure AD Device portal. We remove it permanently from your account.
    Do confirm that you are not able to see the device in this portal :

    81852-image.png

    Are you still having issues ?


  2. OG 1 Reputation point
    2021-06-08T14:10:55.137+00:00

    Hi, I have the exact same issue.
    In Authenticator, how do I unregister my phone in one account, so I can use this phone for 'sign-in with phone' function for the other account?

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.