A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
To regain access when the Microsoft Authenticator app is the only sign-in method and the phone has been changed, the account’s MFA settings must be reset by an administrator or by Microsoft support.
Since this is a business/partner account and the only available method is the Authenticator app (no working SMS or alternate method), the following options apply:
- If there is another administrator in the organization
- Ask that admin to reset multifactor authentication (MFA) for the account in Microsoft Entra ID:
- Go to Microsoft Entra admin center (https://entra.microsoft.com).
- Navigate to Users → All users and select the user account.
- Open Authentication methods.
- Choose Require re-register multifactor authentication.
- After this reset, sign in again; the portal will prompt to set up Microsoft Authenticator from scratch using a new QR code.
- Ask that admin to reset multifactor authentication (MFA) for the account in Microsoft Entra ID:
- If this is the only administrator account for the tenant
- The Microsoft Data Protection team must be involved to verify identity and reset access:
- Call Microsoft support using the appropriate Customer service phone numbers - Microsoft Support entry.
- When the automated system asks for the problem, state that the issue is with Authenticator for an Office 365 for business/company account.
- Confirm that this is an administrator account and that there are no other admins.
- Ask the agent to open a service request and route it to the Data Protection team to reset MFA and restore access to the admin account.
- Be prepared to provide:
- The administrator email address.
- The tenant domain.
- Error messages seen when trying to sign in.
- Confirmation that this is the only admin account.
- The Microsoft Data Protection team must be involved to verify identity and reset access:
- If the subscription is through a partner/reseller
- Contact the reseller’s support and ask them to open a Microsoft support ticket on behalf of the tenant, explaining that the only global admin is locked out due to Authenticator and needs MFA reset by the Data Protection team.
- After Microsoft resets MFA
- Sign in to the account again.
- When prompted for more information, set up the Microsoft Authenticator app on the new phone:
- Install the app.
- Sign in to the service (for example, Microsoft 365 or Partner Center) with username and password.
- Follow the prompts to scan the QR code and complete registration.
This process is required because forum moderators and tools cannot bypass or change MFA for an admin account; only another admin or Microsoft’s support/Data Protection team can do it.
References:
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- Use a screen reader to set up and troubleshoot multifactor authentication
- Common problems with two-step verification for a work or school account