Authenticator problem following phoe change

Francis Aubut 5 Reputation points
2026-03-15T18:54:32.59+00:00

Hi, I'm an independant IT and I changed my phone, after verifying I thought everything was fine, I initialize to factory default my old phone, then I found out that in Microsoft Authenticator I have some account with an action required to activate them on my new phone. Since I am the only admin of some of these account and I have not set another method to authenticate, what is the best way to erase the method so I can confgure them back with my new phone.

Thank you.

Francis Aubut

Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Oldest
  1. AI answer

    2026-03-15T18:54:47.5333333+00:00

    Because the accounts use Microsoft Authenticator as the only MFA method and the old phone was wiped, the MFA methods must be reset by an administrator or by Microsoft support; they cannot be erased directly from the new phone.

    Use the following options depending on each tenant:

    1. If there is another Global Administrator in the tenant
      • Ask that admin to reset the MFA methods so they can be configured again on the new phone:
        1. Go to Microsoft Entra admin center (https://entra.microsoft.com).
        2. Navigate to Users → All users and select the affected account.
        3. Open Authentication methods.
        4. Select Require re-register multifactor authentication.
        5. The next sign-in for that user will prompt to set up Microsoft Authenticator again on the new phone.
    2. If there is no other Global Administrator (only one admin on the tenant)
      • This is a tenant lockout scenario. The only supported way to clear/reset the MFA methods is through Microsoft’s Data Protection team:
        1. Call Microsoft global customer service using the phone number for the region from Customer service phone numbers - Microsoft Support.
        2. In the IVR/with the agent, clearly state:
          • The issue is with Authenticator and Office 365 for business.
          • It is a company account (not education/personal).
          • The caller is the only administrator and is locked out due to MFA on a lost/erased phone.
          • A service request with the Data Protection team is needed to reset the admin’s authentication methods.
        3. Be prepared to provide tenant and admin details and business verification so Data Protection can validate identity and reset the MFA.
    3. If support is hard to reach
      • As a workaround, create a temporary trial tenant only to open a support ticket:
        1. Sign up for a Microsoft 365 trial tenant (business/enterprise plan).
        2. In that new tenant, go to the Microsoft 365 admin center and open a support ticket.
        3. In the ticket, explain that access is needed to a different existing tenant where the requester is the only admin locked out by MFA, and request escalation to the Data Protection team.
        4. After the original tenant is recovered, cancel the trial subscription to avoid charges.

    Once Data Protection or another admin resets MFA, sign in again and reconfigure Microsoft Authenticator on the new phone for each affected account.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.