A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
For both personal and school accounts, access must be recovered by using alternative verification methods or having an admin/support team reset the Microsoft Authenticator requirement.
- Personal Microsoft account (Outlook/Hotmail/Xbox, etc.)
- Go to the Microsoft account dashboard and sign in with email and password.
- On the MFA prompt, choose “Use a different verification option” (such as SMS, email code, or security key) if any were previously configured.
- After signing in, go to Security → Advanced security options and under “Ways to prove who you are” remove the old Authenticator registration and add the new phone (Authenticator, SMS, or other methods).
- If no other method works and access to Authenticator is permanently lost, follow the account recovery flow from the sign-in page and use the available recovery methods. Support agents cannot send codes or bypass verification, so working recovery info is required.
- School or work (organization) account
- If this is a school or work account and there is an IT/admin team, contact the organization’s help desk or Microsoft 365 administrator and ask them to reset MFA for the account in Microsoft Entra Admin Center. After reset, sign in again and re-register the Authenticator app on the new phone.
- If this is a business tenant and the account is the only global admin and is locked out due to Authenticator:
- Call Microsoft using the Customer service phone numbers - Microsoft Support entry and clearly state that:
- This is an Office 365 for business / company account.
- It is an admin account.
- There are no other admins.
- A Data Protection team escalation is needed to reset MFA and restore access.
- If phone support cannot be reached, create a new trial Microsoft 365 tenant, go to the new tenant’s Admin Center → Support → Help & support, and open a ticket explaining that the request is for a different, existing tenant where the only global admin is locked out by MFA. Provide tenant name, admin UPN, and error details so the Data Protection team can verify identity and reset MFA.
- Call Microsoft using the Customer service phone numbers - Microsoft Support entry and clearly state that:
- After access is restored
- Install Microsoft Authenticator on the new phone.
- Re-register the personal and school/work accounts for MFA.
- Add at least one backup method (SMS, email, or security key) so that sign-in is still possible if the phone is lost again.
- For personal accounts that are passwordless, if Authenticator is lost, temporarily add a password back via Additional security options so that recovery is easier next time.
If none of the alternative methods are available and there is no admin or Data Protection path (for example, a personal account with no working recovery info), access cannot be restored without successful verification.
References:
- How to go passwordless with your Microsoft account
- Common problems with two-step verification for a work or school account
- Microsoft Authenticator FAQs
- Back up your accounts in Microsoft Authenticator
- Restore account credentials from Microsoft Authenticator
- How to sign out from Authenticator
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- How Do I Regain Access to My Account After Losing Access to Microsoft Authenticator? (Urgent Request). - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A