A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
The 6-digit vs 8-digit difference comes from using different verification methods:
- Microsoft 365 sign-in with Microsoft Authenticator normally uses push notifications (Approve / Deny) or a 6‑digit verification code when configured as an MFA method.
- The app can also show OATH one-time passwords (OTP) for other accounts, which may be 6 or 8 digits, depending on how that account was set up. Those 8‑digit codes are not accepted where a 6‑digit Microsoft 365 MFA code is expected.
To fix the mismatch, configure Microsoft Authenticator specifically as the verification method for the Microsoft 365 account and then use the code shown under that account entry:
- In a browser, sign in to Microsoft 365 and go to the security/MFA setup page (for work/school, this is usually done via the organization’s security info/MFA setup flow).
- Choose Microsoft Authenticator (or Mobile app / Authenticator app) as the method.
- Follow the prompts to add a work or school account in the Authenticator app and scan the QR code shown on the screen.
- After setup, tap the correct Microsoft 365 account entry in Authenticator. It should display a 6‑digit code (or send a push notification to Approve), which can be used on the sign-in page.
If the sign-in page explicitly asks for a 6‑digit code and the Microsoft 365 account entry in Authenticator does not show a “one-time password code” line at all, the account is not correctly registered for code-based MFA. In that case, the MFA settings must be reset and reconfigured by an administrator via the organization’s Entra/Microsoft 365 admin process so that the correct 6‑digit code or push notification is available.
References: