A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
The error is expected behavior. Before removing an existing verification method (like Microsoft Authenticator or “Send sign-in notification”), at least one other valid security contact method must be on the account.
To proceed, the sequence must be:
- Add a new security method first
- Go to the Microsoft account Security page, then Advanced security options.
- Select Add a new way to sign in or verify.
- Add a phone number, alternate email address, or another approved method.
- Complete the verification for this new method (enter the code sent to the phone/email).
- Then remove the old “send sign-in notification” / Authenticator method
- Still on Advanced security options, under Ways to prove who you are / verification options, find the entry for Microsoft Authenticator, App, or Send sign-in notification.
- Expand that entry and select Remove.
- Confirm Remove again.
Important constraints from the security system:
- Old security info does not need to be removed unless there is a security risk, but if it must be removed, new info must be added first.
- If all security information is removed or scheduled for removal, the account goes into a 30‑day restricted state where security settings and billing info cannot be changed.
So to clear the error, add at least one new phone or email as security info, verify it, and then remove the legacy app / notification method.
References: