A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
The 6‑digit code is the one‑time password (OTP) that should appear inside the Microsoft Authenticator app for the specific work account. If the app is only showing a sign‑in screen asking for a 6‑digit code (and not showing an account entry with a “One‑time password code” line), the account is not properly set up in Authenticator and the code cannot be generated on that device.
To resolve this, use one of these paths:
- Try another sign‑in method (if available)
- On the sign‑in screen where the 6‑digit code is requested, look for options like:
- “I don’t have a code”
- “Use a different verification option”
- SMS, phone call, or email verification
- If any of these are configured on the account, use them to sign in and then update the Authenticator registration.
- If no alternative method works (work/school account)
- This is a work account protected by MFA. When the Authenticator app is lost, reset, or not showing the OTP, the MFA registration must be reset by the organization.
- Contact the organization’s IT/help desk or Microsoft 365/Entra administrator and ask them to reset the MFA settings for the account in the Microsoft Entra admin center and require re‑registration of multifactor authentication.
- After they reset MFA, sign in again; the portal will prompt to set up Microsoft Authenticator from scratch (scan QR code), and the 6‑digit OTP will then appear in the app.
- If the user is the only admin in the tenant
- If this is a business tenant and the affected account is the only global admin, and there is no way to sign in, contact Microsoft support by phone and request escalation to the Data Protection team to reset the MFA methods for the tenant admin account. Use the “Customer service phone numbers - Microsoft Support” page referenced in the context to find the correct number.
Until the Authenticator registration is reset and re‑set up, the 6‑digit code will not appear, and sign‑in will remain stuck in this loop.
References: