A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Because the old phone is broken and the app on the new phone is asking for a code from the old device, the existing MFA setup must be updated so that the new phone (or another method) can be used for verification.
Use one of these approaches, depending on what is still accessible:
- If there is still any access to the account (for example, on a PC browser)
- Sign in to the account in a browser.
- Go to the Additional security verification / Security info page: this is where sign-in methods (phone, Authenticator, etc.) are managed.
- Remove the old phone/Authenticator method:
- Tab to the entry for the old phone or Authenticator and choose Delete.
- Add a new method for the new phone:
- Choose Add sign-in method → select Phone or Microsoft Authenticator.
- For phone: enter the phone number and complete verification.
- For Authenticator: install the Microsoft Authenticator app on the new phone and follow the prompts to scan the QR code and complete setup.
- If there is no way to complete MFA at all (locked out)
- For personal Microsoft accounts: use the account recovery flow and choose I don’t have any of those when asked for verification methods, then follow the recovery steps. This may temporarily remove or reset MFA so that Authenticator can be set up again on the new phone.
- For work or school accounts where this is the only admin account and no other admin can reset MFA:
- A tenant admin MFA reset is required by Microsoft support/Data Protection. Contact Microsoft Support by phone (Customer service phone numbers - Microsoft Support) and clearly state that this is a tenant admin lockout due to Authenticator on a lost/broken phone, and that there is no other admin. The Data Protection team can verify identity and reset the authentication methods so the new phone can be enrolled.
- If the issue is specifically “Authentication did not complete” on the new phone
- Ensure the Microsoft Authenticator app on the new phone is:
- Unlocked.
- Updated to the latest version.
- Allowed to show notifications.
- On a working network, with correct date and time.
- Then retry the sign-in and approval.
- Ensure the Microsoft Authenticator app on the new phone is:
Once access is restored, add at least one backup method (SMS, alternate phone, or another email) so a future phone loss does not cause lockout.
References:
- Use a screen reader to set up and troubleshoot multifactor authentication
- Troubleshoot problems with Microsoft Authenticator
- Back up your accounts in Microsoft Authenticator
- Troubleshoot signing in with a passkey
- Authenticator Did Not Complete Login
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Cannot authenticate with E-mail when logging into Microsoft Authenticator(iOS). - Microsoft Q&A