A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
For the three work/school accounts where Microsoft Authenticator was the only verification method and the old phone is wiped, the accounts cannot be directly reconnected to the app from the new phone. The verification methods must first be reset or replaced through the account’s security settings or by an administrator/support team.
Use the following options depending on what access still exists and what type of account each one is:
- Work or school accounts with an organizational IT/help desk
- Contact the organization’s IT/help desk for each affected work/school account.
- Explain that the old phone with Microsoft Authenticator was wiped and there are no alternative verification methods configured.
- Ask them to clear or reset the MFA/two-step verification settings for the account.
- After they clear the settings, sign in again with username and password. The next sign-in will prompt to set up two-step verification from scratch.
- On the new phone, install Microsoft Authenticator and follow the registration prompts to add the account.
- During setup, add at least one backup method (SMS, phone call, or email where allowed) so there is another way to verify if the phone is replaced again.
This path is required for work/school accounts when there is no access to the old device and no backup methods; only the organization’s admin/help desk can reset those MFA settings.
- Work or school accounts where another verification method might exist
If any of the three accounts had more than one method configured (for example, SMS, office phone, or email):
- At the MFA prompt, choose Sign in another way (or similar option).
- Select a listed alternative method (SMS, call, etc.) and complete verification.
- After signing in, go to the account’s security info page and:
- Add the Microsoft Authenticator app on the new phone.
- Keep the existing backup methods or add new ones.
If Sign in another way does not appear, there are no other methods configured and the IT/help desk reset described above is the only option.
- Personal Microsoft accounts (if any of the three are personal accounts)
For personal Microsoft accounts, verification code issues and missing backup methods are handled through the self-service flows:
- When prompted for a code from Microsoft Authenticator, select I don’t have my Microsoft Authenticator app.
- If backup security info (phone/email) is available, select it and complete verification.
- If there is no access to any listed methods, select I don't have any of these and follow the prompts to update security info, as described in the verification-code troubleshooting guidance. This may trigger a security waiting period if all security info is changed at once.
Relevant behavior and limitations from the documentation
- Push notifications may still be going to an old device if the Authenticator app was last used there. When that device is gone or wiped, the notification cannot be approved and another method or reset is required.
- If no alternative methods are configured and the device with Authenticator is lost, the only supported paths are:
- Use the I don't have any of these flow for personal accounts to update security info.
- Have an admin/help desk or Microsoft’s Data Protection team (for single-admin tenants) reset MFA for work/school accounts.
- For tenants where there is only one global admin and that admin is locked out due to Authenticator on a lost phone, Microsoft’s Data Protection team must be engaged via a support ticket or phone support to restore access.
After access is restored and the new phone is set up with Microsoft Authenticator for each account, configure multiple verification methods (Authenticator plus SMS/phone/email where allowed) and keep security info up to date to avoid lockout the next time a device is replaced.
References:
- Common problems with two-step verification for a work or school account
- Microsoft Authenticator FAQs
- Troubleshoot unrequested verification codes
- Troubleshoot Microsoft verification code issues
- Reasons why verification codes don't always arrive
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work.
- Cannot authenticate with E-mail when logging into Microsoft Authenticator(iOS).
- My personal hotmail account hacked by hacker with authentication app enabled.
- Requesting a Tenant Admin MFA Reset
- Severity A Situation - Locked out of global admin account (MFA) - business down