A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Because the account is protected by Microsoft Entra multifactor authentication (MFA) and the configured method (phone/app) is no longer available, access must be restored by an administrator with sufficient rights or by Microsoft support, depending on whether there are other admins in the tenant.
Use the appropriate path below:
- Try another verification method (if any exist)
- On the MFA prompt, select Other verification options (or similar) and choose a different method (SMS, phone call, or another app) if it is listed.
- If a phone method is configured but not working, verify that the phone number is correct in the user’s account settings once access is regained.
- If there is another Global/Authentication Admin in the tenant Ask that admin to reset the MFA registration so the account can be set up again:
- The other admin signs in to the Microsoft Entra admin center.
- Go to Entra ID > Users.
- Select the affected user account.
- Open Authentication methods.
- Select Require re-register multifactor authentication.
After this, the next sign-in will prompt for MFA registration again, allowing configuration of Microsoft Authenticator or another method from scratch.
If sign-in is still blocked due to phone-based MFA issues, the other admin should also:
- Check that Block sign in is not enabled on the user.
- Confirm the correct phone numbers are set on the user object.
- If there is no other Global Admin (you are the only admin) When the only global admin is locked out and cannot complete MFA, the tenant is effectively locked. In this situation, recovery must be handled by Microsoft’s Data Protection/Tenant Recovery team via a support case. Forum moderators or normal admins cannot reset this for the tenant.
Required action:
- Contact Microsoft support using the appropriate customer service phone number for the region (see “Customer service phone numbers - Microsoft Support” in the referenced articles).
- When prompted by the automated system, clearly state that this is an Authenticator / MFA lockout on an Office 365/Microsoft 365 for business or Microsoft Entra ID admin account and that there is no other global admin.
- The frontline agent will open a Data Protection / Tenant Recovery service request. Be prepared to provide tenant details and verification information so ownership can be validated.
Once Microsoft verifies identity and restores access, sign in again and:
- Reconfigure MFA methods (Microsoft Authenticator, phone, etc.).
- Consider adding at least one additional global admin and multiple MFA methods (e.g., Authenticator + phone) to avoid future lockouts.
- If repeated attempts have triggered security limits If many sign-in attempts have already been made, Microsoft Entra MFA may temporarily block additional attempts as a security measure. In that case:
- Wait and try again later, or
- Use a different MFA method if one is available.
If no alternative method exists and no other admin can reset MFA, proceed with the Data Protection support path above.
References:
- You don't receive a text or voice call that contains the verification code for Microsoft Entra multifactor authentication
- Authentication methods in Microsoft Entra ID - Voice call
- Manage user authentication methods for Microsoft Entra multifactor authentication
- Common problems with two-step verification for a work or school account
- Frequently asked questions about Microsoft Entra multifactor authentication
- I need to reset my mfa methods - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Global Admin Locked out - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A