A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
To regain access to a business/work account when the phone with Microsoft Authenticator is lost, the MFA methods must be reset by an administrator or by Microsoft support, depending on the situation.
- Try any alternative sign-in method
- If another MFA method was configured (SMS, phone call, office phone, security key, etc.), use it on the sign-in page by choosing “Sign in another way” and complete sign-in.
- After signing in, update security verification methods so they point to a new phone or Authenticator app. For work/school accounts, this is typically done from the Security info or Additional security verification page.
- If another admin exists in the tenant
- Ask a Global Admin in the organization to reset MFA for the account:
- In Microsoft Entra admin center, they go to Users → All users → [your account] → Authentication methods.
- Use Require re-register multifactor authentication so that all MFA methods are cleared and you are forced to register new methods on next sign-in.
- This is the standard way to recover when a user loses access to the Authenticator app.
- Ask a Global Admin in the organization to reset MFA for the account:
- If you are the only admin on the tenant
- When there is only one administrator and that admin loses access to MFA, the Microsoft Data Protection team must perform the reset after verifying identity.
- Call Microsoft’s global customer service using the numbers in Customer service phone numbers - Microsoft Support and request a Data Protection / tenant admin MFA reset for a business (Office 365/Microsoft 365) account.
- In the automated/agent flow, clearly state:
- The issue is with Authenticator / MFA.
- The product is Office 365/Microsoft 365 for business.
- It is a company account.
- You are the only administrator and are locked out due to MFA.
- Ask them to open a service request and route it to the Data Protection team to reset the admin’s MFA methods.
- If support is hard to reach
- As a workaround, create a temporary trial tenant:
- Sign up for a Microsoft 365 business/enterprise trial (new tenant).
- In the new tenant’s admin center, go to Support → Help & support and open a ticket.
- In the ticket, explain that the real problem is with a different, existing tenant where you are the only admin and are locked out by MFA, and request escalation to the Data Protection team.
- This trial tenant is only a channel to contact support; it does not give access to data in the locked tenant.
- As a workaround, create a temporary trial tenant:
Once Microsoft support/Data Protection verifies identity and resets MFA, sign in again to the original business account; you will be prompted to set up Microsoft Authenticator and/or other MFA methods on the new phone.
References:
- Common problems with two-step verification for a work or school account
- Use a screen reader to set up and troubleshoot multifactor authentication
- Can't use Azure Multi-Factor Authentication to sign in to cloud services after you lose your phone or the phone number changes
- Work or school account help
- Frequently asked questions about Microsoft Entra multifactor authentication
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- I need to reset my mfa methods - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Microsoft Authenticator app doesn't show 6-digit OTP code - Microsoft Q&A