A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Use of the Microsoft Authenticator app on a new phone depends on whether there is another sign-in method available and whether this is a work/school (Microsoft Entra / Azure AD) account.
- Try an alternative verification method
- On the sign-in screen where the Authenticator approval is requested, choose “Sign in another way” (or similar link).
- If any other method is configured (SMS, phone call, office phone, email, security key), select it and complete sign-in.
- After signing in, go to your Security info / Additional security verification page and:
- Remove the old phone/Authenticator entry.
- Add the new phone and reconfigure Microsoft Authenticator.
- If the old phone is still available
- Install/open Microsoft Authenticator on the old phone.
- Approve the sign-in request there.
- Once signed in, follow the steps above to remove the old device and add the new one.
- Then install Authenticator on the new phone and add the account again as described in Download and install the Microsoft Authenticator app.
- If there is no alternative method and no access to the old phone
- For a work or school account, contact the organization’s IT help desk or Microsoft 365/Entra administrator and ask them to reset MFA for the account:
- In Entra admin center they can go to Users → [your user] → Authentication methods and choose Require re-register multifactor authentication so that MFA setup is forced again on next sign-in.
- If this is a business tenant and the account is the only global admin and is locked out, the tenant admin MFA reset must be handled by Microsoft’s Data Protection team via a support ticket, as described in the Q&A references:
- Call the regional Customer service phone numbers - Microsoft Support line.
- When prompted by the IVR, clearly indicate: “Authenticator”, “Office 365 for business”, “company account”, “administrator”, and that there is no other admin.
- Ask to create a service request and be routed to the Data Protection team to reset the admin’s authentication methods.
- If direct phone support cannot be reached, create a temporary trial Microsoft 365 tenant, go to its admin center, and open a support ticket from there explaining that access is needed to a different, existing tenant where you are the only admin.
- If still signed in on a computer
- If there is an active session in a browser or desktop app, go immediately to the account’s Security info or Additional security verification page and:
- Remove the old phone/Authenticator.
- Add a new phone number and/or re-register the Authenticator app on the new phone.
- If all methods are lost and no admin/help desk is available
- For a work/school account, only the organization’s admin or Microsoft’s Data Protection team can clear MFA settings. End users and forum moderators cannot bypass MFA.
References:
- Use a screen reader to set up and troubleshoot multifactor authentication
- Microsoft Authenticator FAQs
- Migrate to a new iPhone for work
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A