A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Because the old phone still holds the registered Microsoft Authenticator, sign-in is looping by sending approvals to a device that is no longer available. The way out depends on whether any other sign-in method is still available and whether this is a work/school or personal account.
- Try any alternative sign-in method
- If SMS, phone call, or email are configured as additional methods, choose those instead of the Authenticator app when prompted.
- If codes are not arriving, follow the guidance to troubleshoot missing verification codes and then update security info:
- For work/school accounts, sign in to the Security info page and select Update info to choose a method that works or I don't have any of these to replace security info. See: Common problems with two-step verification for a work or school account.
- For personal Microsoft accounts, sign in to the Security basics page, select Update info, then choose a working method or I don't have any of these to replace security info. See: Troubleshoot Microsoft verification code issues.
- If the phone was replaced and MFA is tied only to the old Authenticator
- For work or school accounts:
- If an admin is available, ask them to reset MFA:
- In Microsoft Entra admin center, they can go to Users → All users → [your account] → Authentication methods and select Require re-register multifactor authentication so that the next sign-in lets registration of Authenticator on the new phone. This is described in the moderator guidance in similar locked-out scenarios.
- If no other admin exists and this is the only admin account, Microsoft’s Data Protection team must be involved. Use the regional Customer service phone numbers - Microsoft Support line and request a ticket with the Data Protection team to reset the admin’s MFA, as outlined in the moderator answers for single-admin lockout cases.
- If an admin is available, ask them to reset MFA:
- If still signed in somewhere (PC or browser)
- While still signed in, immediately update security info so the new phone can be added and the old Authenticator reference removed:
- For work/school accounts, open the Security info page (via View account → Update info) and add a new phone or method, then install Microsoft Authenticator on the new device and register it.
- For personal accounts, go to the Security basics page, select Update info, add a new phone/email, and then set up Microsoft Authenticator on the new phone.
- If no method works and no admin/help desk is available
- For work/school accounts where the user is not an admin, contact the organization’s help desk or Microsoft 365 admin and ask them to clear or reset MFA settings so registration can be done again on the new phone. This is the recommended path in similar “spiral”/lockout cases.
- For personal Microsoft accounts where all security info is inaccessible, use I don't have any of these during sign-in to start the account recovery flow and follow the prompts to prove identity and add new security info.
Once access is restored and the new phone is set up, remove any old phone/Auth app entries from the Security info page so future sign-ins no longer send approvals to the old device.
References:
- Common problems with two-step verification for a work or school account
- Troubleshoot Microsoft verification code issues
- Use a screen reader to set up and troubleshoot multifactor authentication
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A