A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
This loop happens when Microsoft Authenticator is the only sign-in method and the old registration is still tied to a device or app instance that can’t be used anymore. The app cannot generate a code until the account’s MFA registration is reset from the server side.
Use the path that matches the type of account:
- Work or school (Microsoft 365 / Entra ID) account
- If there is any other verification method on the account (SMS, alternate email, security key), use that instead of Authenticator when prompted.
- After signing in, go to the Security info page and update the sign-in methods (remove the broken Authenticator registration and add it again).
- If Authenticator is the only method and sign-in is impossible, contact the organization’s IT/Help desk or tenant admin and ask them to reset MFA for the account in the Microsoft Entra admin center (Users → the user → Authentication methods → “Require re-register multifactor authentication”). After that, sign in again and re‑set up Authenticator from scratch.
- Personal Microsoft account where Authenticator is stuck
- If there is another method (SMS or email code), choose “Use a different verification option” or equivalent and sign in with that.
- Once signed in, remove the old Authenticator registration and add it again.
- If there is no other method and no admin (personal account only), recovery requires contacting Microsoft support so the Data Protection team can verify identity and reset MFA from their side, as described in the Q&A guidance.
In all cases, the core fix is: do not try to add the same broken Authenticator entry again; instead, have MFA reset (by an admin or Microsoft support), then re‑register the account in the Authenticator app using the new QR code or setup instructions.
References: