A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
For a new phone, the Microsoft Authenticator app cannot be used to sign in until the account and MFA methods are reconfigured. The exact steps depend on whether there is another MFA method available and what type of account is in use.
- If another MFA method is available (SMS, phone call, alternate app)
- On the sign-in screen, choose Use a different verification option (or similar) and select SMS/phone or another configured method.
- After signing in successfully, go to the Additional security verification / Security info page and remove the old phone, then add the new phone and reconfigure Authenticator:
- Delete the old phone entry.
- Select Add sign-in method → choose Phone or Authenticator app and follow the prompts to register the new device.
- For detailed steps on adding the new phone and removing the old one, see the guidance under “I have a new mobile phone and I want to add it to MFA.”
- If no alternative MFA method works and this is a work or school (Microsoft Entra / Microsoft 365) account
- MFA must be reset by an administrator:
- Ask a global admin in the tenant to open Microsoft Entra Admin Center and use Require re-register multifactor authentication for the user so MFA methods can be set up again on the new phone.
- If this is a business account and the user is an end user, contact the organization’s IT/admin help desk and request an MFA reset.
- If this is a business account and the locked-out user is the only global admin, Microsoft’s Data Protection team must assist via a support ticket raised through Customer Support. The support process is described in the referenced Q&A threads.
- MFA must be reset by an administrator:
- If repeated attempts are failing
- Multiple failed sign-in attempts can temporarily block MFA sign-in. Wait and try again later or use a different MFA method if available.
- If the issue persists, the tenant admin should review Microsoft Entra sign-in logs and, if needed, open a support case.
- After MFA is reset or an alternate method is used to sign in
- Install Microsoft Authenticator on the new phone using the instructions in Download and install the Microsoft Authenticator app.
- Sign in and follow the prompts to add the work or school account again using the QR code or setup link provided during MFA setup.
If none of the above is possible (no alternate method, no other admin, and the user is the only admin), the only supported path is to work with Microsoft Support/Data Protection as outlined in the Q&A references to regain access and then re-register MFA on the new phone.
References:
- Use a screen reader to set up and troubleshoot multifactor authentication
- Troubleshoot problems with Microsoft Authenticator
- Common problems with two-step verification for a work or school account
- Enable passwordless sign-in with Authenticator
- I need to reset my mfa methods - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A