A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
For a personal Microsoft account with two-step verification enabled, recovery options are very limited by design.
Based on the described situation:
- Two-step verification (2FA) is turned on.
- Microsoft Authenticator is no longer available on any device.
- No backup of Authenticator was configured and the 25‑digit recovery code cannot be found.
- Password reset and the account recovery form both still ask for a second factor.
When 2FA is enabled and none of the configured second-factor methods (Authenticator, SMS, email, recovery code, etc.) are accessible, support cannot bypass or reset security info for the account. This is explicitly enforced to protect the account and its contents:
If you have turned on two-step verification and cannot access any of the alternate methods to get a verification, we cannot help you, sorry. To protect your account and its contents, our support agents are not allowed to send password reset links or access and change account details.
That means:
- Standard Microsoft account support and Authenticator support cannot unlock or reset the account without a working second factor.
- The Microsoft account recovery form cannot override 2FA.
- Chat or phone agents can only direct to the same self-service flows already tried.
The only possible ways back into the account are:
- Regain access to at least one existing 2FA method that was previously configured (for example, finding the 25‑digit recovery code, recovering an old phone number or email that is still on the account, or restoring a valid Authenticator backup as described in the Authenticator restore documentation).
- If that is not possible, the account remains inaccessible; there is no supported method for Microsoft to remove or reset 2FA on a personal account when all second-factor methods are lost.
For future protection on any new or recovered accounts:
- Enable backup in Microsoft Authenticator and verify it works.
- Add multiple security info methods (phone, alternate email, Authenticator, recovery code) and keep them up to date.
- Store the 25‑digit recovery code in a safe place.
References: