A cloud-based identity and access management service for securing user authentication and resource access
Because the accounts use Microsoft Authenticator as the only MFA method and the old phone was wiped, the MFA methods must be reset by an administrator or by Microsoft support; they cannot be erased directly from the new phone.
Use the following options depending on each tenant:
- If there is another Global Administrator in the tenant
- Ask that admin to reset the MFA methods so they can be configured again on the new phone:
- Go to Microsoft Entra admin center (https://entra.microsoft.com).
- Navigate to Users → All users and select the affected account.
- Open Authentication methods.
- Select Require re-register multifactor authentication.
- The next sign-in for that user will prompt to set up Microsoft Authenticator again on the new phone.
- Ask that admin to reset the MFA methods so they can be configured again on the new phone:
- If there is no other Global Administrator (only one admin on the tenant)
- This is a tenant lockout scenario. The only supported way to clear/reset the MFA methods is through Microsoft’s Data Protection team:
- Call Microsoft global customer service using the phone number for the region from Customer service phone numbers - Microsoft Support.
- In the IVR/with the agent, clearly state:
- The issue is with Authenticator and Office 365 for business.
- It is a company account (not education/personal).
- The caller is the only administrator and is locked out due to MFA on a lost/erased phone.
- A service request with the Data Protection team is needed to reset the admin’s authentication methods.
- Be prepared to provide tenant and admin details and business verification so Data Protection can validate identity and reset the MFA.
- This is a tenant lockout scenario. The only supported way to clear/reset the MFA methods is through Microsoft’s Data Protection team:
- If support is hard to reach
- As a workaround, create a temporary trial tenant only to open a support ticket:
- Sign up for a Microsoft 365 trial tenant (business/enterprise plan).
- In that new tenant, go to the Microsoft 365 admin center and open a support ticket.
- In the ticket, explain that access is needed to a different existing tenant where the requester is the only admin locked out by MFA, and request escalation to the Data Protection team.
- After the original tenant is recovered, cancel the trial subscription to avoid charges.
- As a workaround, create a temporary trial tenant only to open a support ticket:
Once Data Protection or another admin resets MFA, sign in again and reconfigure Microsoft Authenticator on the new phone for each affected account.
References:
- Frequently asked questions about Microsoft Entra multifactor authentication
- Troubleshoot problems with Microsoft Authenticator
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- I need to reset my mfa methods - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- Use a screen reader to set up and troubleshoot multifactor authentication
- Microsoft Authenticator FAQs