A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Because the Microsoft Authenticator app was removed and there is no backup, the multi-factor authentication (MFA) registration must be reset from the account’s identity provider side; it cannot be recovered from the app itself.
Use the appropriate path based on the type of account:
- Work or school (Microsoft 365 / Entra ID) account
- If this is a work or school account and there is another administrator in the organization, request that admin to reset MFA:
- Admin signs in to Microsoft Entra admin center (https://entra.microsoft.com).
- Go to Users → All users and select the locked-out user.
- Open Authentication methods.
- Select Require re-register multifactor authentication.
- The next time the user signs in, they will be prompted to set up the Authenticator app again with a new QR code.
- If this is a business account and the user is an end user, contact the organization’s Microsoft 365/Entra administrator and ask them to perform the above steps.
- If this is a business tenant and the locked-out user is the only global admin, contact Microsoft support by phone and request the Data Protection team to reset the MFA for the tenant admin. Use the regional number from Customer service phone numbers - Microsoft Support and clearly state that this is a tenant admin MFA lockout and there is no other global admin.
- If this is a work or school account and there is another administrator in the organization, request that admin to reset MFA:
- Personal Microsoft account (Outlook.com, Hotmail, etc.)
- If this is a personal Microsoft account and the Authenticator backup cannot be restored, use alternative sign-in recovery options (email, SMS, or account recovery forms). If access to the backup account is also lost, support agents cannot restore Authenticator credentials directly. In that case, use the Microsoft account sign-in helper to regain access to the Microsoft account, then reconfigure MFA and the Authenticator app.
- If Authenticator backup cannot be restored
- When the app has been removed and there is no usable backup, the accounts themselves are not lost, but each protected account must be re-added to Authenticator after MFA is reset by an admin or by the Data Protection team, or after regaining access via account recovery.
Once MFA is reset and access to the account is restored, reconfigure Microsoft Authenticator and, if supported, enable backup so that future device changes do not cause lockout.
References:
- Restore account credentials from Microsoft Authenticator
- Back up your accounts in Microsoft Authenticator
- Microsoft Authenticator FAQs
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- I need to reset my mfa methods - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Microsoft Authenticator app doesn't show 6-digit OTP code - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- Microsoft Invest - Troubleshoot Multi-Factor Authentication (MFA)