A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
If the PIN works to open Microsoft Authenticator but fails when approving the sign-in, check these items in order:
- Make sure Authenticator is fully unlocked before approving
If the app is locked, the approval entry box might not appear correctly and authentication can fail. - Check whether App Lock is enabled
Authenticator can require the device PIN or biometric again when approving a sign-in notification, even if the app already opened. This is expected behavior when App Lock is turned on. - Update Microsoft Authenticator
An outdated app version can cause authentication failures. Install the latest available update from the device app store. - Check notifications and network connectivity
Make sure notifications are enabled for Authenticator and the device has internet access. If needed, switch between Wi-Fi and mobile data. - Verify device date and time
Incorrect date or time settings can prevent authentication from completing. - Restart the device
This can clear temporary app or sign-in issues. - If the problem continues, send logs from the app
In Authenticator, open the top-level menu and select Send feedback before contacting support or the IT admin. - If using a work or school account, contact the IT admin
If the issue persists after the steps above, the IT admin should investigate or reset the authentication method.
If the device is Android and biometric sign-in recently changed, note that changing the device PIN or changing biometric type can invalidate a passkey, which requires signing in with another method and creating a new passkey.
References: