Share via

Revoke my MS authentication in Azure portal

Anuja G 0 Reputation points
2026-03-27T12:12:05.71+00:00

As my MS authentication is set in a lost mobile , Please guide me how to revoke my MS authentication in Azure portal

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Most helpful
  1. Q&A Assist
    2026-03-27T12:12:31.6566667+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    If the Microsoft Authenticator app is on a lost phone, the goal is to reset or revoke the existing MFA setup so a new device can be registered.

    There are two main paths, depending on whether this is a work/school (Microsoft Entra ID) account and whether an admin is available.

    1. If this is a work or school account and an admin is available

    Ask an Authentication Administrator or other Microsoft Entra admin in the organization to reset MFA for the account in the Microsoft Entra admin center:

    1. Admin signs in to the Microsoft Entra admin center at https://entra.microsoft.com.
    2. Go to Entra ID > Users.
    3. Select the affected user account.
    4. Select Authentication methods.
    5. Select Require re-register multifactor authentication.

    This action removes existing Microsoft Authenticator registrations and other MFA methods listed (phone numbers, Authenticator apps, software OATH tokens). Next time sign-in occurs, the system will prompt to set up MFA again on a new phone.

    If there are multiple registered sign-in methods and the user can still sign in via another method (for example SMS or phone call), the user can also clean up old Authenticator registrations directly:

    1. Go to https://aka.ms/mysecurityinfo.
    2. Review the list of sign-in methods.
    3. Delete the entries corresponding to the old Authenticator app/device.
    4. Add the new Authenticator app on the new phone when prompted.
    5. If this is a work or school account and there is no other admin

    If the locked-out account is the only global/admin account in the tenant, an internal admin cannot reset MFA. In this case, a support ticket must be opened so Microsoft’s Data Protection team can reset MFA and restore access. This is done via Microsoft support channels (phone or support request) as shown in the referenced Q&A examples; once they reset MFA, sign in again and register the Authenticator app on the new device.

    1. If this is a personal Microsoft account

    For personal accounts, the same principle applies: use an alternate sign-in method if available (SMS, email, etc.) to access security info and remove the old Authenticator method at https://aka.ms/mysecurityinfo. If no alternate method is available and full lockout occurs, contact Microsoft consumer support so the Data Protection or account recovery process can reset MFA.

    In all cases, after MFA is reset or old methods are removed, sign in again and follow the prompts to add Microsoft Authenticator on the new phone.


    References:

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.