A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Follow these steps to regain access when two-factor prompts or passkeys no longer appear in Microsoft Authenticator:
- Confirm what the ArcGIS account is asking for
ArcGIS Online can be configured to use:- Time-based one-time passcodes (6‑digit OTP), or
- Passwordless/passkey (FIDO2) sign-in via Microsoft Authenticator.
- A 6‑digit code from an authenticator app, or
- Approval of a notification / passkey (face, fingerprint, PIN) on the device.
- Open Microsoft Authenticator and check the account entry
- Open the app and tap the ArcGIS-related account entry.
- If there is a line like “One-time password code” with a 6‑digit code, use that code on the ArcGIS sign-in page.
- If there is no one-time password code and no passkey prompt appears when signing in, the registration for that account may be incomplete or removed.
- Check for orphaned or invalid passkeys
If the ArcGIS sign-in is using a passkey (FIDO2) and the passkey was removed or invalidated on the identity provider side, the credential stored on the device becomes an orphaned passkey. In that case:- Remove the old passkey or account entry related to that ArcGIS login from the Authenticator app or from the device’s passkey manager.
- After cleanup, the account owner (ArcGIS Online tenant admin) must re-register a new passkey for the account.
- If the account is locked behind MFA and cannot be re-registered
Because the ArcGIS Online account is outside the organization and requires MFA to even start reconfiguration, only the ArcGIS Online tenant administrators or the identity provider admins (for example, Microsoft Entra ID admins, if that’s what backs the ArcGIS account) can:- Reset the MFA settings for that user, or
- Remove the current Authenticator registration and allow re-registration.
- If nothing appears in Authenticator at all
- Ensure the app is updated to the latest version and that notifications are allowed.
- If the ArcGIS login is using passkeys via cross-device authentication (for example, browser on PC + phone), make sure Bluetooth and internet connectivity are enabled on both devices, as required for passkey cross-device flows.
- If prompts still never arrive and no OTP is visible, the registration is almost certainly broken and must be reset by the ArcGIS/IdP admin as described above.
In summary, the ArcGIS Online administrators (or their identity provider admins) must reset the MFA / passkey registration for that external account so a new Microsoft Authenticator registration or passkey can be created. Until that reset is done, sign-in will remain blocked because the existing passkey or OTP configuration is no longer valid.
References:
- Troubleshoot signing in with a passkey
- Sign in with a passkey (FIDO2) for your work or school account
- Sign in with passkeys in Authenticator for Android and iOS devices
- Authenticator Did Not Complete Login
- Microsoft Authenticator app doesn't show 6-digit OTP code - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A