A cloud-based identity and access management service for securing user authentication and resource access
Because the account uses Microsoft Entra multifactor authentication and there is only one administrator, the lost or broken Microsoft Authenticator registration cannot be fixed directly by signing in.
Use the following options based on the situation:
- If there is any other global administrator in the tenant
- Ask that administrator to reset MFA so a new Authenticator registration can be done:
- Sign in to the Microsoft Entra admin center as a user administrator or global administrator.
- Go to Entra ID > Users.
- Select the affected user account.
- Open Authentication methods.
- Select Require re-register multifactor authentication.
- Sign in again on the affected account and complete MFA setup with the new Authenticator app.
- Ask that administrator to reset MFA so a new Authenticator registration can be done:
- If truly the only administrator on the tenant
- Self-service recovery is not possible; Microsoft must verify identity and reset MFA:
- Call Microsoft’s global customer service phone number from the Customer service phone numbers - Microsoft Support page.
- In the IVR or with the agent, clearly state:
- The problem is with Authenticator / MFA.
- The product is Office 365/Microsoft 365 for business.
- It is a company (work) account, not education or personal.
- The caller is the only administrator and is locked out at the MFA step.
- A Data Protection / Tenant Recovery or similar team is needed to reset MFA for the tenant admin.
- Work with the Data Protection team to verify identity and have them reset the MFA methods on the admin account.
- Self-service recovery is not possible; Microsoft must verify identity and reset MFA:
- If support cannot be reached directly
- Create a temporary trial tenant only to open a support ticket:
- Sign up for a Microsoft 365 trial to create a new tenant.
- Sign in to the Microsoft 365 Admin Center of this new tenant.
- Go to Support → Help & support and open a ticket.
- In the ticket, specify that access is needed to a different existing tenant where the caller is the only global admin but locked out at MFA, and request escalation to the Data Protection team.
- After the original tenant is recovered, cancel the trial subscription to avoid charges.
- Create a temporary trial tenant only to open a support ticket:
Until Microsoft resets the MFA registration, sign-in will continue to fail at the Authenticator step even if the password is correct.
References:
- Common problems with two-step verification for a work or school account
- Problems signing in to a Microsoft application
- Troubleshoot application sign-in
- Can't set up MFA because five devices are already registered to use an authenticator app
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- I cant log in to my business account because it is requiring Authenticator app which I do not have - Microsoft Q&A
- Global Admin Locked out - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Authenticator Did Not Complete Login