A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
To escape the Microsoft Authenticator loop, another verification method or an admin reset is required. The options depend on whether this is a personal Microsoft account or a work/school (Microsoft Entra ID) account.
- If this is a personal Microsoft account
- Go to the Microsoft account dashboard and sign in with username and password.
- Under Security > Advanced security options, look under Ways to prove who you are for other methods (SMS, email, etc.).
- Use one of those other methods to verify identity and then remove or change the Authenticator-based method on the old device:
- Find the line that shows Send sign-in notification and the old device name.
- Expand it and select Remove so that sign-in no longer depends on that Authenticator instance.
- After that, re-add Microsoft Authenticator on the current device using the normal setup flow.
If no other sign-in/verification method is configured and only Authenticator is available, self-service recovery is not possible; support escalation is required (see work/school guidance below for the pattern).
- If this is a work or school account and there IS another admin
- Ask another Microsoft Entra ID admin to reset MFA for the account:
- In the Azure/Microsoft Entra admin portal, go to Microsoft Entra ID > Users.
- Select the user.
- Open Authentication methods.
- Select Require re-register multifactor authentication.
- After this, sign in again; the account will be prompted to set up Authenticator from scratch on the new device.
- If this is a work or school account and there is NO other admin (only one global admin)
- This is the “endless loop” scenario described in the Q&A references: the only way out is a reset by Microsoft’s Data Protection team via a support case.
- The documented pattern is:
- Call the regional Microsoft support number for business/commercial support.
- When prompted by the IVR, clearly indicate:
- Using Office 365/Microsoft 365 for business.
- It is a company account.
- Caller is the administrator.
- There is no other administrator.
- A service request is needed to reset MFA / speak with the Data Protection team.
- In several documented cases, once the call reaches the correct team, a Data Protection engineer verifies identity and then resets MFA on the tenant admin account so that a new Authenticator registration or alternate method can be added.
- If reaching a live agent is difficult, one documented workaround is to create a temporary trial Microsoft 365 tenant, use that to open a support ticket from the Admin Center, and ask support to involve the Data Protection team for the original tenant.
- General notes
- Deleting or reinstalling Authenticator alone does not break the loop; the server-side MFA methods must be changed or reset (either by self-service using another method, by an admin, or by Microsoft support/Data Protection).
- For future resilience, once access is restored, configure at least two different MFA methods (for example, Authenticator plus SMS or email) so that losing one method does not cause another lockout.
References:
- How to go passwordless with your Microsoft account
- Common problems with two-step verification for a work or school account
- Can't set up MFA because five devices are already registered to use an authenticator app
- Troubleshoot Microsoft verification code issues
- How Do I Regain Access to My Account After Losing Access to Microsoft Authenticator? (Urgent Request). - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- I cant log in to my business account because it is requiring Authenticator app which I do not have - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A