I am locked out of my Azure subscription due to a Microsoft Authenticator issue after changing phones.

Iain Hinchliffe 0 Reputation points
2026-06-14T18:04:58.3766667+00:00

I am locked out of my Azure subscription due to a Microsoft Authenticator issue after changing phones.

Symptoms:

  • Password authentication succeeds.
  • Microsoft Authenticator push notifications succeed.
  • Azure Portal then requires a 6-digit verification code.
  • My current Microsoft Authenticator app only contains my Microsoft Account registration and does not generate the required Azure MFA code.
  • The old phone was replaced in April 2026 and later wiped/sold.
  • I cannot access Azure Portal, Billing, or MFA setup pages.
Community Center | Not monitored

1 answer

Sort by: Most helpful
  1. AI answer

    2026-06-14T18:05:18.7566667+00:00

    Because password and push approval succeed but Azure then asks for a 6‑digit code that the current Microsoft Authenticator app does not have, the issue is an incomplete or missing Azure MFA (OATH/code) registration for the Entra ID account on the new phone.

    There are only two supported recovery paths in this situation, depending on whether there is another administrator in the tenant.

    1. If there is another global administrator in the tenant

    Ask another cloud/global administrator to reset the MFA registration so the account can be re‑enrolled on the new phone:

    1. That admin signs in to the Azure portal.
    2. Opens Microsoft Entra ID.
    3. Goes to Users and selects the affected user account.
    4. Opens Authentication methods.
    5. Selects Require re‑register multifactor authentication (or equivalent “require contact methods again”).
    6. Saves the change.

    After this, sign in again:

    1. Enter the password.
    2. Complete any existing MFA step that still works (for example, SMS or a working method, if present).
    3. When prompted to set up MFA, add Microsoft Authenticator on the new phone and complete the QR‑code setup so that the 6‑digit verification codes for Azure are created in the app.

    This process forces Azure Multi‑Factor Authentication to treat the account as not enrolled and lets it be fully re‑registered on the new device.

    1. If there is no other global administrator (only one admin, now locked out)

    When the locked account is the only global admin, self‑service recovery is not possible. In this case, Microsoft’s Data Protection team must verify ownership and reset MFA from the backend.

    Follow the pattern described for single‑admin lockouts:

    1. Contact Microsoft Support via the published customer service phone numbers for the region.
    2. Clearly state that this is an administrator account locked out due to MFA / Authenticator and that there is no other global admin in the tenant.
    3. The frontline agent opens a Data Protection / Tenant Recovery ticket.
    4. The Data Protection team then verifies identity and tenant ownership (business documentation, domain, subscription details, etc.).
    5. After verification, they reset the MFA registration for the admin account so that sign‑in can proceed and MFA can be re‑enrolled on the new phone.

    If the subscription is through a partner/reseller and the global admin cannot open a ticket, the partner’s support channel can open a Microsoft support request on behalf of the tenant.

    Once access is restored

    After support or another admin resets MFA and sign‑in works again:

    1. Go to the Security info / Additional security verification page.
    2. Remove any old or obsolete phone/Auth app entries (for the wiped/sold phone).
    3. Add Microsoft Authenticator on the new device and complete both notification and code (OATH) setup so that:
      • Push approvals work, and
      • A 6‑digit verification code is available for Azure MFA.
    4. Optionally add backup methods (SMS/phone) to avoid future lockouts.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.