A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
If the only verification method is Microsoft Authenticator on the old phone, and the new phone is asking for a code that cannot be provided, the account’s MFA methods must be updated or reset using an alternative path.
Use one of these approaches, depending on the type of account and what is still accessible:
- If another verification method is configured (phone/email)
- When signing in and prompted for Authenticator, choose the option such as I don’t have my Microsoft Authenticator app or I don’t have a code.
- If offered SMS or email, select that method and complete verification.
- After signing in, go to the Security info / Additional security verification page and add the new phone or Authenticator app as a method:
- For work/school accounts: sign in to the Security info page and use Update info to add a new phone or app method, or choose I don't have any of these to replace security info if existing methods no longer work.
- For personal Microsoft accounts: if the backup phone/email is no longer accessible, select I don't have any of these during sign-in and follow the prompts to update backup security info.
- If verification codes are not arriving
- Avoid making excessive or repetitive requests for codes, as this can cause temporary blocking of verification code delivery.
- Check if the phone is blocking texts from unknown numbers; if so, change the setting and then choose I don't have a code to have another code sent.
- Ensure a mobile (non‑VOIP) number is used and that the SMS inbox is not full.
- If completely locked out of a work or school (business) tenant and you are the only admin
- When no other admin can reset MFA and the Authenticator on the old phone is unavailable, the Microsoft Data Protection team must assist.
- Call Microsoft’s customer service phone number for the region and, in the automated prompts, indicate:
- The issue is with Authenticator.
- The product is Office 365 for business / company account.
- Confirm being an administrator and that there is no other administrator.
- Ask to open a service request and be routed to the Data Protection team for an admin MFA reset.
- If direct phone support cannot be reached, create a temporary trial Microsoft 365 tenant, go to the admin center of that new tenant, and open a support ticket requesting Data Protection team assistance for the original locked tenant.
- If still signed in on a trusted device (PC or browser)
- If there is an active session on a computer, sign in to the account’s security settings from that device and:
- Add a new phone number or Authenticator method.
- If necessary and allowed, temporarily disable or reset MFA, then re‑register the new phone.
If none of the above options are available (no backup methods, no trusted device, and no other admin), recovery must go through the Microsoft account recovery/sign‑in helper and/or Data Protection support, and access will only be restored after identity verification.
References:
- Use a screen reader to set up and troubleshoot multifactor authentication
- What happens if there's an unusual sign-in to your account
- Troubleshoot Microsoft verification code issues
- Common problems with two-step verification for a work or school account
- Set up a mobile device as a two-step verification method
- Microsoft Authenticator FAQs
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Cannot authenticate with E-mail when logging into Microsoft Authenticator(iOS). - Microsoft Q&A
- I need to reset my mfa methods - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A