A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
For a business (work or school) account where Microsoft Authenticator is not giving a code and phone verification is also failing, the next steps depend on whether there is another admin who can help.
- If this is an end‑user account (not an admin)
- Contact the organization’s IT administrator or Help desk and ask them to reset multifactor authentication (MFA) for the account in the Microsoft Entra admin center.
- After the admin clears the MFA settings, sign in again; the account will be prompted to re‑register MFA and can set up Microsoft Authenticator from scratch.
- If this is an admin account and there is another admin
- Ask another global admin in the tenant to:
- Go to the Microsoft Entra admin center → Users → All users → select the affected user → Authentication methods.
- Use the option to require re‑register multifactor authentication / clear MFA methods.
- Then sign in again and re‑set up the Authenticator app when prompted.
- Ask another global admin in the tenant to:
- If this is the only admin on the tenant
- This situation requires Microsoft’s Data Protection team to reset MFA, because no one in the tenant can change the admin’s MFA settings.
- Call Microsoft support using the regional Customer service phone numbers and ask the frontline agent to open a ticket with the Data Protection team for an admin MFA reset on the tenant.
- When navigating the phone system (IVR), clearly state that the problem is with “Authenticator” for an “Office 365 for business” company account, that this is the administrator account, and that there is no other admin. Confirm that a service request is needed and that the case must go to the Data Protection team.
- If support is hard to reach by phone (workaround)
- Create a temporary trial Microsoft 365 tenant (a new, separate tenant) using a trial subscription.
- Sign in to the new tenant’s Microsoft 365 Admin Center and open a support ticket from there.
- In the ticket, explain that access is needed to a different, existing tenant where the account is the only admin and MFA is blocking sign‑in. Provide the locked tenant’s domain and admin UPN and request Data Protection team assistance for MFA reset.
- After the original tenant issue is resolved, cancel the trial subscription to avoid charges.
If phone and Authenticator both cannot verify identity, only an admin (or Microsoft’s Data Protection team when there is no other admin) can reset the MFA configuration; it cannot be bypassed from the sign‑in page.
References:
- Common problems with two-step verification for a work or school account
- "Account verification system is having trouble" error message when you try to sign in by using a work or school account
- Troubleshoot Microsoft verification code issues
- I cant log in to my business account because it is requiring Authenticator app which I do not have - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- Microsoft Authenticator app doesn't show 6-digit OTP code - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A