Try these steps in order:
- Check whether the sign-in request is going to an old phone. If Microsoft Authenticator was last used on a previous device, the push notification can be sent there instead of the current phone. If the old phone is still available, open Authenticator there and approve the sign-in.
- In the sign-in screen, choose Other ways to sign in or a different verification method if available, such as SMS or phone call.
- Open Microsoft Authenticator on the current phone and make sure:
- the app is unlocked
- notifications are enabled and not silent
- the account is still listed in the app
- the app is updated to the latest version
- Check the phone connection and device settings:
- switch between Wi-Fi and mobile data
- make sure date and time are correct
- restart the phone
- If text or phone verification is being used instead of app approval, avoid repeated requests. Too many attempts can trigger a temporary block. Microsoft recommends trying up to five times in 5 minutes for phone call or text message authentication.
- If multiple sign-in attempts were already made, wait and try again later, or use a different MFA method. Repeated attempts can cause Microsoft Entra multifactor authentication to temporarily prevent additional attempts.
- If the Authenticator account is missing from the app, or the phone was changed and the app is no longer registered, the MFA registration may need to be reset. For a work account, contact the organization's IT admin or Help desk to clear or reset MFA settings so Authenticator can be registered again.
- If the mobile device was lost or stolen, sign in with a different method if available, and ask the organization's Help desk to clear the old settings.
If the issue continues after these steps, open Authenticator, go to the app's top-level menu, select Send feedback to send logs, then contact the organization's IT admin or Help desk.