A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
The account is stuck in an MFA loop where Microsoft Authenticator is the only verification method and cannot complete sign-in. The recovery options depend on whether this is a work/school (business) account and whether there is another admin.
- If this is a work or school (Microsoft 365 business) account and there is another admin
- Ask another cloud services/Microsoft 365 admin to reset the Multi-Factor Authentication settings for the account.
- They should:
- Sign in to the cloud service portal as an admin.
- Go to
https://account.activedirectory.windowsazure.com/usermanagement/multifactorverification.aspx. - Select the affected user account.
- Select Manage user settings.
- Select Require selected users to provide contact methods again, then select Save.
- After this, sign in again and re-register the Authenticator app or another MFA method when prompted.
- If this is a work or school account and there is no other admin (you are the only admin)
- This requires Microsoft Data Protection team intervention.
- Call Microsoft support using the regional number from Customer service phone numbers - Microsoft Support (from the context articles).
- When navigating the phone menu/IVR, clearly indicate:
- The problem: “Authenticator” / “lost access to Authenticator and MFA”.
- Product: “Office 365 for business” / “Microsoft 365 for business”.
- Account type: “Company account”.
- Role: “I am the only administrator; there is no other admin”.
- Request: A service request with the Data Protection team to reset admin MFA.
- If reaching an agent is difficult, one documented workaround is:
- Create a new temporary Microsoft 365 trial tenant using a trial plan.
- Sign in to the new tenant’s Microsoft 365 Admin Center.
- Use Help & support to open a ticket and explicitly state that access is needed to a different, existing tenant where you are the locked-out admin and need MFA reset by the Data Protection team.
- After the original tenant is fixed, cancel the trial to avoid charges.
- If this is a work/school account and you are an end user (not an admin)
- Contact the organization’s Microsoft 365/Entra ID admin or Help desk.
- Ask them to:
- Go to Microsoft Entra admin center → Users → All users → select the user → Authentication methods.
- Use Require re-register multifactor authentication (or equivalent) to clear MFA so it can be set up again.
- If the phone was lost or replaced
- If any other sign-in method is configured (SMS, voice call, security key, etc.), use that method instead of Authenticator to sign in once, then update MFA methods.
- If no alternative method works, follow the admin reset paths above (another admin or Data Protection team).
Until an admin or Microsoft support resets MFA, sign-in cannot be completed if Authenticator is the only method and is unavailable.
References:
- Can't use Azure Multi-Factor Authentication to sign in to cloud services after you lose your phone or the phone number changes
- Common problems with two-step verification for a work or school account
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- I cant log in to my business account because it is requiring Authenticator app which I do not have - Microsoft Q&A
- How Do I Regain Access to My Account After Losing Access to Microsoft Authenticator? (Urgent Request). - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Authenticator Did Not Complete Login