Share via

MFA Codes in Authenticator App for Shared Company Account

Anonymous
2026-02-23T20:06:05.36+00:00

We have removed all users, devices, and authentication methods associated with the account. We do not see any remaining registrations tied to them in the admin portal. However, they are still receiving MFA verification prompts on their phone.

We need to fully remove their Authenticator registration and ensure there are no lingering authentication methods or cached sessions tied to this account?

Microsoft 365 and Office | Subscription, account, billing | For business | Other
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Vy Nguyen 9,475 Reputation points Microsoft External Staff Moderator
    2026-02-23T21:34:04.5566667+00:00

    Hi Anonymous, 

    Welcome to the Microsoft Q&A forum. 

    Thank you for the thorough cleanup you have already performed and for bringing this to my attention. Based on the details you shared, a former employee continues to receive Microsoft Authenticator verification prompts for your shared company account even after you removed their users, devices, and authentication methods in the admin portal.  

    This situation typically occurs because tenant wide protections still require multifactor for all users, which can continue to surface prompts to any Authenticator app that previously held the account. Furthermore, a per user multifactor setting or existing refresh tokens may keep triggering notifications until registrations are reset and sessions are revoked. Consequently, you might not see an active method in the portal, yet prompts can still appear on the former employee’s device. 

    To address this in a way that suits your situation, please consider the following steps below: 

    1/ Review Security Defaults in Microsoft Entra 

    • Sign in to the Microsoft Entra admin center with an administrator account. 
    • Go to Overview, open Properties, and select Manage security defaults. 
    • Check the status: 
      • If Security defaults is enabled, the service enforces multifactor for all users, including shared and older accounts. This means prompts are sent during sign in and may appear on any Authenticator app that previously added the account until registrations are cleared and sessions are refreshed. 
      • If Security defaults is disabled, users can sign in with only a password, which reduces protection. I do not recommend leaving it disabled for normal operations.  User's image

    For your reference: Configure Security Defaults for Microsoft Entra ID - Microsoft Entra | Microsoft Learn 

    2/ Verify and adjust per user MFA for the shared account and any related legacy users 

    • Open the Microsoft 365 admin center and go to Users, then Active users. 
    • Select Multifactor authentication to open the per user MFA page. 

    User's image

    • Search for the shared account and any old user objects that were ever tied to it. 
    • Review the State column: 
      • If it shows Enabled or Enforced for the shared account, change it to Disabled specifically for this account to stop prompts while you reset its methods.  User's image

    I hope this information is helpful. Please follow these steps and let me know if it works for you. If you have any updates regarding the issue, please feel free to share them with me.       

    Thank you for your patience and your understanding. I look forward to continuing the conversation. 


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment”.    

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread. 


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.