A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
The loop occurs because the account is configured so that Microsoft Authenticator is the only verification method, and changing MFA settings itself requires successful MFA. To break this loop, a different verification method or an administrator/Data Protection intervention is required.
Use the following options depending on the account type and role:
- If this is a work or school (Microsoft Entra / Microsoft 365) account and there is an admin
- Contact the organization’s Microsoft 365/Entra administrator.
- The admin should:
- Go to Microsoft Entra admin center (https://entra.microsoft.com).
- Navigate to Users → All users → [select the user] → Authentication methods.
- Use Require re-register multifactor authentication to reset MFA for the user.
- After this reset, sign in again and register Microsoft Authenticator plus at least one alternative method (SMS, phone call, etc.).
- If this is a work or school account and the locked-out user is the only admin
- Microsoft Data Protection team must assist.
- Call Microsoft support using the regional Customer service phone numbers - Microsoft Support entry.
- When the automated system asks, clearly indicate:
- Issue: “Authenticator”
- Product: “Office 365 for business”
- Account type: “Company account”
- Role: “Administrator”
- Confirm there are no other admins.
- Ask to open a service request and escalate to the Data Protection team to verify identity and reset MFA on the admin account.
- If there are multiple admins but this user is locked out
- Ask another global admin to perform the same reset steps in the Entra admin center (see option 1).
- If SMS or phone verification is configured but not working reliably
- Try up to five times within 5 minutes to receive a call or text, as Microsoft uses multiple telecom providers.
- If still failing, open a support case as described above.
- If text messages are unreliable, prefer Microsoft Authenticator or phone call as the primary method once access is restored.
- General guidance to avoid future loops
- Always configure more than one MFA method (e.g., Authenticator + SMS or phone call).
- When changing phones, ensure Authenticator and backup methods are working before wiping the old device.
References:
- Frequently asked questions about Microsoft Entra multifactor authentication
- Authentication methods in Microsoft Entra ID - Voice call
- Common problems with two-step verification for a work or school account
- Authentication did not complete
- Troubleshoot problems with Microsoft Authenticator
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- How Do I Regain Access to My Account After Losing Access to Microsoft Authenticator? (Urgent Request). - Microsoft Q&A
- Cannot authenticate with E-mail when logging into Microsoft Authenticator(iOS). - Microsoft Q&A
- Having problems getting text codes to confirm my account - Microsoft Q&A
- Use a screen reader to set up and troubleshoot multifactor authentication