A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Follow these steps based on the current access and the loss of Microsoft Authenticator:
- If the password is known and there is access to at least one security method (phone or email):
- Go to the Advanced security options page and sign in using the account password.
- When prompted to verify identity, choose SMS or email instead of the Authenticator app.
- After signing in, select Add a new way to sign in or verify and add a new method (for example, a new phone number, email, or re‑set up Microsoft Authenticator).
- Once the new method is confirmed, expand the old Authenticator/security method that is no longer accessible and select Remove.
- Do not remove all security info at once, otherwise the account may be restricted for 30 days.
- If the password is known but there is no access to any existing security info (for example, every prompt insists on the Authenticator and there is no usable SMS/email option):
- Start signing in to the Microsoft account.
- At the Verify your identity screen, select I don't have any of these.
- Follow the instructions to replace the security info.
- After the replacement is completed, there is a mandatory 30‑day wait before normal sign‑in is allowed. During this period, if the old security info becomes available again and is used to sign in, the pending change is cancelled.
- If the password is forgotten and there is no access to any security info:
- Use the account recovery process instead of normal sign‑in.
- First review the guidance in Help with the Microsoft account recovery form.
- Then submit the request via the Account recovery form, providing as much accurate information as possible.
- If two‑step verification was turned on and none of the alternate verification methods are accessible anymore:
- Support agents cannot send verification codes, reset passwords, or turn off two‑step verification on behalf of the user.
- The only available paths are:
- Replace security info via I don't have any of these (if the password is known), then wait the 30‑day period; or
- Use the account recovery form (if the password is not known and no security info is available).
Two‑factor authentication cannot be disabled without successfully completing one of the verification or recovery flows above.
References: