A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
This loop happens when Authenticator is the only verification method on the account and there is no alternative way configured.
To break out of the loop, use one of these approaches depending on the type of account:
- For work or school accounts (Microsoft Entra / Microsoft 365)
- Sign in using any other method that is already configured for the account (for example, SMS, email code, or another authenticator method) if available.
- If no other method works and Authenticator is the only factor, the account’s MFA must be reset by an administrator:
- Contact the organization’s Help desk or Microsoft 365/Microsoft Entra administrator.
- The admin signs in to the Microsoft Entra admin center.
- Go to Identity → Users → All users.
- Select the affected user → Authentication methods.
- Select “Require re-register multifactor authentication.”
- After this, the next sign-in will prompt to set up Authenticator again with a QR code instead of asking for a code from the existing app.
- If this is a business account and there is only one global admin and that admin is locked out, a support ticket with Microsoft’s Data Protection team is required, raised via Microsoft support phone or via another tenant as described in the context.
- For personal Microsoft accounts
- Ensure there is at least one other sign-in verification method configured (email, passkey, or another authenticator app):
- Go to the Microsoft account Security tab at https://account.microsoft.com/security.
- Select “Manage how I sign in.”
- Select “Add a new way to sign in or verify” and add an email, authenticator app, or passkey.
- Then add Authenticator properly:
- On the Security tab, select “Manage how I sign in.”
- Select “Add a new way to sign in or verify.”
- Choose “Use an app.”
- Follow the instructions to show a QR code.
- In Authenticator, tap the plus icon → Personal account → Scan a QR code and scan the code.
- If there is no working alternative method and access to the account dashboard is not possible, account recovery is required; support agents cannot bypass verification or send codes directly.
- General guidance to avoid this loop in future
- Always configure at least one backup method (for example, an additional email or another authenticator app) so that adding or re-adding Authenticator does not depend on the same app for verification.
- For work or school accounts, involve the organization’s admin early if Authenticator is lost or a phone is changed, so they can reset MFA before the old method is removed.
References:
- How to add your accounts to Microsoft Authenticator
- Microsoft account security info & verification codes
- Common problems with two-step verification for a work or school account
- Troubleshoot Microsoft verification code issues
- Authenticator app not sending code to my email - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- Reset Personal Azure MFA - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A