A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
For a work or school (Microsoft Entra ID) account, Azure Multi-Factor Authentication expects the Microsoft Authenticator entry that’s specifically configured for that tenant and sign-in method. An 8-digit code usually indicates that the app entry is not the correct one for the Azure tenant or is configured in a way Azure doesn’t accept for that sign-in, so Azure will continue to prompt for a 6‑digit verification code or a push notification.
From the available information, there’s no supported way to “force” Azure to accept 8‑digit codes or to change the format from 8 to 6 digits on the client side. The supported options are:
- Use push notification or the correct MFA entry
- For Azure MFA, the supported Microsoft Authenticator methods are:
- Push notification approval ("MFA via notifications through mobile app").
- Time-based OATH verification code from the app ("Verification code from mobile app").
- The Azure sign-in page will expect the method that is actually registered for the work/school account in Security info.
- For Azure MFA, the supported Microsoft Authenticator methods are:
- Check and clean up registered Authenticator methods
- Sign in to Security info at https://aka.ms/mysecurityinfo (for Azure commercial/GCC) or https://aka.ms/MySecurityInfo-us (for US Government clouds) and review the list of sign-in methods.
- If there are multiple Authenticator entries or old devices, delete the unneeded ones and re-add Microsoft Authenticator for the work/school account so that it registers correctly as:
- “Microsoft Authenticator: (Notification/Code)” for MFA, or
- “Microsoft Authenticator: Passwordless phone sign-in” for passwordless.
- If the account is at the five‑device limit for authenticator apps, follow the documented process to delete some sign-in methods and then re-register:
- An admin may need to set “Require re-register multifactor authentication” for the user in Microsoft Entra ID.
- Then the user deletes some or all sign-in methods at https://aka.ms/mysecurityinfo and sets up Authenticator again.
- If locked out and unable to complete MFA
- If the user cannot complete any MFA method (no working app entry, no phone, etc.), another admin must reset the user’s MFA settings so that contact methods can be re-registered.
- The documented admin action is to require the user to provide contact methods again, which forces a fresh MFA setup on next sign-in.
- Ensure Authenticator is supported and up to date
- Microsoft periodically retires older Authenticator versions. If the app is out of date or unsupported on the device, it may not work correctly for Azure MFA. Updating to the latest version is required; otherwise, use a supported OATH verification code method as documented.
If none of the registered methods in Security info match the Authenticator entry that is generating codes, the only supported resolution path is to have an admin reset MFA and then re-register Microsoft Authenticator correctly for the Azure tenant, using the standard QR-code or app configuration flow so that Azure and the app agree on the code format and method.
References:
- Authentication methods in Microsoft Entra ID - Microsoft Authenticator app
- Can't set up MFA because five devices are already registered to use an authenticator app
- Can't use Azure Multi-Factor Authentication to sign in to cloud services after you lose your phone or the phone number changes
- Troubleshoot Azure Multi-Factor Authentication issues