A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Based on the described behavior, the account registration in Microsoft Entra ID is out of sync with the Microsoft Authenticator app on the device. Since re-adding the account, disabling MFA, and deleting/re-adding the sign-in method did not help, the next effective step is to fully reset the MFA registration for this user in Microsoft Entra ID and then re-enroll the Authenticator app.
Use the following approaches depending on the role:
- If there is a Microsoft Entra administrator available
- Have an admin go to the Microsoft Entra admin center (https://entra.microsoft.com).
- Navigate to Users → All users → [select the affected user] → Authentication methods.
- Select Require re-register multifactor authentication for the user.
- Optionally, delete existing Authenticator-related sign-in methods for that user at https://aka.ms/mysecurityinfo (if the user can still access this page with another method).
- Next time the user signs in, complete MFA setup from scratch and add the account again in Microsoft Authenticator using the new QR code.
- If the affected user is not an admin
- Contact the organization’s IT admin or Help desk and ask them to reset MFA for the account by using Require re-register multifactor authentication as above.
- After the reset, sign in again and follow the new MFA setup prompts to reconfigure Microsoft Authenticator.
- If the affected user is the only global admin and is locked out
- Contact Microsoft’s Data Protection team via the regional Customer service phone numbers - Microsoft Support channel.
- Clearly state that this is a tenant admin MFA lockout and that there is no other administrator who can reset MFA.
- Work with the Data Protection team to verify identity and have them reset the MFA configuration on the tenant admin account.
- While waiting for the Authenticator feedback ticket
- If another MFA method (SMS, phone call, or another authenticator app) is configured and working, use that method to sign in and then:
- Go to https://aka.ms/mysecurityinfo and remove the existing Authenticator registration.
- Add Microsoft Authenticator again from that page, scanning the new QR code.
- If another MFA method (SMS, phone call, or another authenticator app) is configured and working, use that method to sign in and then:
If repeated sign-in attempts have been made while testing, Microsoft Entra multifactor authentication may temporarily block further attempts as suspicious. In that case, wait before trying again or use a different MFA method if available.
References:
- Common problems with two-step verification for a work or school account
- Can't set up MFA because five devices are already registered to use an authenticator app
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Microsoft Authenticator app doesn't show 6-digit OTP code - Microsoft Q&A
- I need to reset my mfa methods - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A