Tag not monitored by Microsoft.
Because password and push approval succeed but Azure then asks for a 6‑digit code that the current Microsoft Authenticator app does not have, the issue is an incomplete or missing Azure MFA (OATH/code) registration for the Entra ID account on the new phone.
There are only two supported recovery paths in this situation, depending on whether there is another administrator in the tenant.
- If there is another global administrator in the tenant
Ask another cloud/global administrator to reset the MFA registration so the account can be re‑enrolled on the new phone:
- That admin signs in to the Azure portal.
- Opens Microsoft Entra ID.
- Goes to Users and selects the affected user account.
- Opens Authentication methods.
- Selects Require re‑register multifactor authentication (or equivalent “require contact methods again”).
- Saves the change.
After this, sign in again:
- Enter the password.
- Complete any existing MFA step that still works (for example, SMS or a working method, if present).
- When prompted to set up MFA, add Microsoft Authenticator on the new phone and complete the QR‑code setup so that the 6‑digit verification codes for Azure are created in the app.
This process forces Azure Multi‑Factor Authentication to treat the account as not enrolled and lets it be fully re‑registered on the new device.
- If there is no other global administrator (only one admin, now locked out)
When the locked account is the only global admin, self‑service recovery is not possible. In this case, Microsoft’s Data Protection team must verify ownership and reset MFA from the backend.
Follow the pattern described for single‑admin lockouts:
- Contact Microsoft Support via the published customer service phone numbers for the region.
- Clearly state that this is an administrator account locked out due to MFA / Authenticator and that there is no other global admin in the tenant.
- The frontline agent opens a Data Protection / Tenant Recovery ticket.
- The Data Protection team then verifies identity and tenant ownership (business documentation, domain, subscription details, etc.).
- After verification, they reset the MFA registration for the admin account so that sign‑in can proceed and MFA can be re‑enrolled on the new phone.
If the subscription is through a partner/reseller and the global admin cannot open a ticket, the partner’s support channel can open a Microsoft support request on behalf of the tenant.
Once access is restored
After support or another admin resets MFA and sign‑in works again:
- Go to the Security info / Additional security verification page.
- Remove any old or obsolete phone/Auth app entries (for the wiped/sold phone).
- Add Microsoft Authenticator on the new device and complete both notification and code (OATH) setup so that:
- Push approvals work, and
- A 6‑digit verification code is available for Azure MFA.
- Optionally add backup methods (SMS/phone) to avoid future lockouts.
References:
- Can't use Azure Multi-Factor Authentication to sign in to cloud services after you lose your phone or the phone number changes
- Troubleshoot Azure Multi-Factor Authentication issues
- Global Admin Locked out - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A