Microsoft 365 features that help users manage their subscriptions, account settings, and billing information.
Error code 399287 indicates that the phone number used for SMS verification has been flagged with a “bad reputation” and is blocked for MFA/identity verification. When this happens, sign-in and access to the Microsoft 365 admin center can fail if SMS is the only available second factor.
To resolve this and regain access, Microsoft support (specifically the Microsoft Data Protection team) must reset or clear the MFA configuration on the account and remove the block so that sign-in can succeed again.
Action steps:
- Contact Microsoft support and request MFA reset
- Call the appropriate Microsoft customer service or support hotline for the region (see “Customer service phone numbers - Microsoft Support” from the context provided in the Q&A threads).
- When prompted by the automated system, clearly state that the issue is with “Authenticator” or “SMS verification” and that sign-in is blocked by error 399287.
- Indicate that this is for a Microsoft 365/Office 365 for business account and that the caller is the administrator.
- Ask specifically for a service request with the Microsoft Data Protection team to:
- Reset MFA for the admin account, and
- Remove the “bad reputation” block on the phone number used for SMS verification.
- If unable to open a ticket from the locked tenant
- If sign-in to the existing tenant is not possible at all, create a temporary Microsoft 365 trial tenant as described in the Q&A guidance:
- Sign up for a Microsoft 365 trial plan and complete tenant creation.
- Go to the Microsoft 365 admin center for the trial tenant.
- Use Support → Help & support to open a support ticket.
- In the ticket, clearly state that access is needed for a different, existing tenant where the admin is locked out due to error 399287/SMS MFA block, and request Data Protection team assistance.
- After the original tenant access is restored, cancel the trial subscription to avoid charges.
- If sign-in to the existing tenant is not possible at all, create a temporary Microsoft 365 trial tenant as described in the Q&A guidance:
- Be prepared to verify identity and domain ownership
- Support may request information such as:
- Admin account sign-in name.
- Tenant domain name(s) (including any new custom domain just purchased and set as primary).
- Proof of domain ownership (DNS or registrar details).
- This is required before the Data Protection team can reset MFA or remove the phone-number block.
- Support may request information such as:
Once the Data Protection team resets MFA and clears the phone number’s bad reputation flag, sign-in with the Microsoft account and access to the Microsoft 365 admin center should work again, and new MFA methods (Authenticator app, new phone number, etc.) can be configured.
References:
- Microsoft Q&A Unable to Verify Identity for Azure Login – Error 399287
- Azure has blocked myphone number for SMS verification due to a “bad reputation” flag - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- I cant log in to my business account because it is requiring Authenticator app which I do not have - Microsoft Q&A
- Find and fix issues after adding your domain or DNS records
- Error message when you try to verify a domain in Office 365
- Sign in to the Microsoft 365 admin center for volume licensing