Azure Portal login -- Authenticator generates 8-digit code but Azure requires 6-digit code

Tzvika 0 Reputation points
2026-03-06T19:15:10.7866667+00:00

I can't log in to Azure Cloud while having no issues with my personal Microsoft account

I deleted and reinstalled my authenticator app - it is only generating 8 digit codes and not the 6 digit codes required, it does not show any notifications.

Need a way to force authenticator app to generate 6-digit codes or get Azure to accept 8 digits.

similar problem to what is described by https://learn.microsoft.com/en-us/answers/questions/5811449/locked-out-of-azure-portal-authenticator-generates

Microsoft Security | Microsoft Authenticator

1 answer

Sort by: Newest
  1. AI answer

    2026-03-06T19:15:28.88+00:00

    For a work or school (Microsoft Entra ID) account, Azure Multi-Factor Authentication expects the Microsoft Authenticator entry that’s specifically configured for that tenant and sign-in method. An 8-digit code usually indicates that the app entry is not the correct one for the Azure tenant or is configured in a way Azure doesn’t accept for that sign-in, so Azure will continue to prompt for a 6‑digit verification code or a push notification.

    From the available information, there’s no supported way to “force” Azure to accept 8‑digit codes or to change the format from 8 to 6 digits on the client side. The supported options are:

    1. Use push notification or the correct MFA entry
      • For Azure MFA, the supported Microsoft Authenticator methods are:
        • Push notification approval ("MFA via notifications through mobile app").
        • Time-based OATH verification code from the app ("Verification code from mobile app").
      • The Azure sign-in page will expect the method that is actually registered for the work/school account in Security info.
    2. Check and clean up registered Authenticator methods
      • Sign in to Security info at https://aka.ms/mysecurityinfo (for Azure commercial/GCC) or https://aka.ms/MySecurityInfo-us (for US Government clouds) and review the list of sign-in methods.
      • If there are multiple Authenticator entries or old devices, delete the unneeded ones and re-add Microsoft Authenticator for the work/school account so that it registers correctly as:
        • “Microsoft Authenticator: (Notification/Code)” for MFA, or
        • “Microsoft Authenticator: Passwordless phone sign-in” for passwordless.
      • If the account is at the five‑device limit for authenticator apps, follow the documented process to delete some sign-in methods and then re-register:
        • An admin may need to set “Require re-register multifactor authentication” for the user in Microsoft Entra ID.
        • Then the user deletes some or all sign-in methods at https://aka.ms/mysecurityinfo and sets up Authenticator again.
    3. If locked out and unable to complete MFA
      • If the user cannot complete any MFA method (no working app entry, no phone, etc.), another admin must reset the user’s MFA settings so that contact methods can be re-registered.
      • The documented admin action is to require the user to provide contact methods again, which forces a fresh MFA setup on next sign-in.
    4. Ensure Authenticator is supported and up to date
      • Microsoft periodically retires older Authenticator versions. If the app is out of date or unsupported on the device, it may not work correctly for Azure MFA. Updating to the latest version is required; otherwise, use a supported OATH verification code method as documented.

    If none of the registered methods in Security info match the Authenticator entry that is generating codes, the only supported resolution path is to have an admin reset MFA and then re-register Microsoft Authenticator correctly for the Azure tenant, using the standard QR-code or app configuration flow so that Azure and the app agree on the code format and method.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.