Share via

Can't sign into the authenticator app because it needs to authenticate itself

Austin B 0 Reputation points
2026-02-27T18:10:39.5366667+00:00

I can't believe that this issue is even possible with a company as big as Microsoft, but:

  1. I'm trying to sign in to the Microsoft Authenticator app with my work email
  2. In doing so, it says I need to verify my identity by approving a request on the Microsoft Authenticator app.
  3. Obviously, this is impossible, so I click "I can't use my authenticator right now"
  4. The app then offers two options:
    1. "Approve a request on my Microsoft Authenticator app"
    2. "Use a verification code displayed on the Microsoft Authenticator app"

Needless to say, I'm stuck in a loop here. All roads lead to the Microsoft Authenticator app, but it's locked behind its own lock and key.

Please instruct me exactly the steps I need to take, because I've tried every variation the Microsoft Authenticator app provides with no success. Also, please fix this bug. There's no excuse for it existing.

Microsoft Security | Microsoft Authenticator
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Q&A Assist
    2026-02-27T18:10:53.8833333+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    For a work or school account, this behavior means the account is configured so that Microsoft Authenticator is the only allowed multifactor method. When Authenticator is lost or on a new phone, the loop described occurs because there is no alternative verification method available.

    The app itself cannot break this loop. The multifactor authentication (MFA) settings for the account must be reset by an administrator or by Microsoft support so that sign-in can proceed and Authenticator can be set up again.

    Follow the path that matches the situation:

    1. If there is another admin in the organization
    2. Ask the Microsoft 365/Entra ID admin to:
      1. Go to Microsoft Entra admin center: https://entra.microsoft.com
      2. Navigate to Users → All users and select the affected user.
      3. Open Authentication methods.
      4. Select Require re-register multifactor authentication.
    3. After this is done, sign in again to the work account in a browser. MFA will be treated as first-time setup and will show a QR code or setup flow that can be scanned/used by the new Microsoft Authenticator app.
    4. If the affected user is an end user with no admin rights
    5. Contact the organization’s IT help desk or Microsoft 365/Entra admin and provide:
      • Work email address.
      • Description that Authenticator is the only MFA method and the device was changed or lost.
    6. Ask them to reset MFA as above (Require re-register multifactor authentication). After reset, sign-in will allow setting up Authenticator again on the new device.
    7. If the affected user is the only global admin for the tenant

    In this case, only Microsoft’s Data Protection team can unlock the tenant:

    1. Call Microsoft support using the regional Customer service phone numbers.
    2. When the IVR/bot asks, indicate:
      • Product: Office 365/Microsoft 365 for business.
      • Account type: Company (not education).
      • Role: Global administrator.
      • Problem: Locked out due to Microsoft Authenticator / MFA.
    3. Ask explicitly for a ticket to be raised for the Data Protection team to help regain access to the global admin account and reset MFA.
    4. Be prepared to provide business and identity verification details.

    If calling support is difficult, a temporary workaround (for admins) is:

    1. Create a new trial Microsoft 365 tenant from the public trial page.
    2. Sign in to the new tenant’s Microsoft 365 Admin Center.
    3. Use Help & support to open a support ticket.
    4. In the ticket, clearly state that the issue is with a different, existing tenant where the global admin is locked out by MFA and needs Data Protection team assistance.
    5. After resolution, cancel the trial to avoid charges.
    6. If this is a personal Microsoft account (not work/school)

    For personal accounts, ensure there is at least one alternative sign-in method (SMS, email code, security key, or another authenticator app). If none is available and access is lost, recovery must be done through Microsoft’s account recovery and support flows; forum moderators and the app itself cannot bypass MFA.

    The loop described is expected when Authenticator is configured as the only verification method and that method becomes unavailable. The only supported resolution is an MFA reset by an admin or Microsoft support so that a new device can be registered.


    References:

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.