A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Because the Microsoft Authenticator app was deleted, the existing MFA registration must be reset so a new device can be enrolled. The exact steps depend on whether the account is a work/school (Microsoft Entra ID / Microsoft 365) account and whether there is an administrator available.
- If this is a work or school (organizational) account and there is an admin available
- Ask a Global Administrator in the tenant to require MFA re-registration for the account.
- Admin steps (in Microsoft Entra ID):
- Go to the Azure portal and open Microsoft Entra ID.
- Select Users and then select the affected user.
- Under Manage, select Authentication methods.
- Select Require re-register multifactor authentication.
- After this, sign in again; the sign-in flow will prompt to set up MFA from scratch and show a new QR code for Microsoft Authenticator.
- If this is a work or school account and there is no other admin (only one global admin, now locked out)
- This is a tenant lockout scenario. The MFA registration cannot be reset from the portal because no admin can sign in.
- In this case, contact Microsoft support and have a ticket raised to the Data Protection team to reset the MFA methods and restore access. This is the only path when the sole global admin is locked out by MFA.
- If this is a work or school account and there are already five authenticator devices registered
- If the error is that five devices are already registered, delete some sign-in methods so the new device can be added:
- Go to https://aka.ms/mysecurityinfo and sign in.
- In Security info, delete one or more existing Authenticator app or other sign-in methods associated with old devices.
- Then add Microsoft Authenticator again and scan the new QR code when prompted.
- If a passwordless sign-in method is configured, set up another two-factor method (SMS or phone call) first so it can be used to confirm deletion of the old authenticator method.
- If the error is that five devices are already registered, delete some sign-in methods so the new device can be added:
- If this is a personal Microsoft account using Microsoft Authenticator
- Re-register the device with the account in the app:
- Install Microsoft Authenticator on the new device.
- In the app, choose Add account → Personal Microsoft account.
- Sign in with the Microsoft account username and password; this re-registers the device and enables notifications/verification again.
- If notifications were going to an old device, also remove the old device registration:
- Go to the two-step verification area of the Account Security page and turn off verification for the old device, then set up the new device.
- Re-register the device with the account in the app:
- General guidance
- Do not delete the authenticator app in the future while MFA is still required for the account. The app (or another MFA method such as SMS/call) must remain available as long as MFA is enforced.
- If no alternative method (phone, SMS, backup admin) exists and sign-in is impossible, the only supported recovery path for work/school accounts is via Microsoft support and the Data Protection team.
References:
- Can't set up MFA because five devices are already registered to use an authenticator app
- Microsoft Authenticator FAQs
- Use a screen reader to set up and troubleshoot multifactor authentication
- Migrate to a new iPhone for work
- I need to reset my mfa methods - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Microsoft Authenticator app doesn't show 6-digit OTP code - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- Microsoft Curate - Troubleshoot Multi-Factor Authentication (MFA)
- Microsoft Monetize - Troubleshooting MFA
- Microsoft Invest - Troubleshoot Multi-Factor Authentication (MFA)