MFA Login Issue

Malarvannan K V 0 Reputation points
2026-09-07T10:18:31.1166667+00:00

One of our users is currently experiencing an issue while attempting to log in to the Microsoft Admin Centre. The user is not receiving the authentication code in the Microsoft Authenticator app, which is preventing access to the portal.

Microsoft 365 and Office | Subscription, account, billing | For business | Other
0 comments No comments

3 answers

Sort by: Most helpful
  1. Helen Luu 2,695 Reputation points Independent Advisor
    2026-09-07T10:40:51.4833333+00:00

    Hi,

    Since the affected user is your organization’s only Global Administrator, please first check whether they can complete verification using an existing alternative method.

    1. On the verification screen, select 'Sign in another way', if available, and try another method they previously registered. The available options depend on the account’s configuration.
    2. If Authenticator is not showing an approval notification, check that notifications are enabled, turn off Do Not Disturb, and try switching between Wi-Fi and mobile data. Also make sure Authenticator is updated and the phone’s date and time are correct. See Troubleshoot problems with Microsoft Authenticator.

    If these checks do not help and no alternative verification method is available, also they are the only administrator in your organization, you will need to contact the Microsoft Data Protection team for further assistance. Please locate the appropriate support phone number for your country or region and contact Microsoft Support so the frontline team can raise a service request on your behalf: Please try to find the related hotline number to call the frontline and let them raise a ticket for you: Customer service phone numbers - Microsoft Support   

    User's image

    Here are some tips and an example of a prompt to help you navigate the IVR more effectively:   

    (When you call the support number, you may hear an introduction of about 30 seconds such as "you can visit the link...". You can ignore this introduction and wait until you are presented with the options. Then press "1" as a business email user, and again "1" for technical help)        

    In some regions you may initially interact with an automated system, so here is an example of how you can answer the prompts to reach the right team more quickly:   

    • What kind of problem are you experiencing?           
    • Answer: Authenticator           
    • What products do you use?           
    • Answer: Office 365 for business           
    • Is this for an education or company account?           
    • Answer: For companies           
    • Are you an administrator?           
    • Answer: Yes           
    • Are there any other administrators in your organization?           
    • Answer: No. I am the only admin in my tenant            
    • Do you need a... Service request?            
    • Answer: Yes. I need to create a ticket. Please send me direct to the Data Protection Teams.        

    During the call, you will be asked to provide information that verifies your identity and proves ownership of the tenant, such as your organization name, billing information, contact email, phone number, or other subscription‑related details.

    If you are unable to reach support via the phone numbers, there is a workaround you might consider: You can register for a new Microsoft 365 tenant by signing up for a trial subscription here: Microsoft 365 Business Plans and Pricing | Microsoft 365    

    User's imageUser's image

    Once the new tenant is created, you can access the admin center and submit a support ticket from there, requesting to speak with the Data Protection Team on behalf of your original tenant.    

    Important notes:     

    • This new trial tenant will not give you access to any of the data or settings in your original locked tenant. It is solely a temporary means to contact Microsoft support.    
    • The resolution time might be longer as you are contacting support from a different tenant.    
    • Remember to cancel the trial subscription for the new tenant once your issue with the original account is resolved to avoid any unintended charges.  

    I hope the information provided helps guide you in the right direction. Although I’m unable to take direct action, I sincerely hope that the steps and recommendations I’ve shared can support you through the process.

    Was this answer helpful?

    0 comments No comments

  2. Malarvannan K V 0 Reputation points
    2026-09-07T10:21:23.64+00:00

    they are only one global admin

    Was this answer helpful?

    0 comments No comments

  3. AI answer

    2026-09-07T10:18:48.52+00:00
    1. Have the user try up to five times within 5 minutes to trigger the MFA prompt again.
    2. In the Microsoft Authenticator app, confirm the app is unlocked, notifications are enabled, and the app is updated to the latest version.
    3. Check for device issues:
      • Verify the phone has internet access.
      • Switch between Wi-Fi and mobile data.
      • Confirm the device date and time are correct.
    4. On the sign-in page, select Other verification options and try a different method if one is available.
    5. If the user normally expects a code in Microsoft Authenticator, open the app and verify whether the account entry is present and responsive.
    6. If the user has made many sign-in attempts, wait and try again later or use a different MFA method. Repeated attempts can trigger protection that temporarily blocks more attempts.
    7. If text or phone verification is being used as a fallback, confirm the phone number is correct. Third-party security apps on the phone can also block verification texts or calls.
    8. If the issue continues, an admin should check the user account in the Azure portal:
      • Go to Microsoft Entra ID > Users > select the affected user.
      • Check whether Block sign in is enabled, and disable it if it is enabled.
    9. If another Global Administrator or Authentication Administrator is available, reset the user’s MFA methods by requiring re-registration of multifactor authentication. This removes existing MFA methods and forces the user to set them up again at next sign-in.
    10. If the user still cannot complete authentication, capture Authenticator logs from Send feedback in the app and contact the organization’s IT admin or helpdesk. If no alternate admin can assist, open a support case.

    Note: Requiring MFA re-registration removes the user’s existing authentication methods. Ensure the user is ready to register a new method before doing this.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.