A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
To remove Microsoft Authenticator (or any verification method) from a Microsoft account when the old phone is no longer available, remove that sign-in verification method from the account’s security settings.
For a personal Microsoft account (Outlook.com, Hotmail, etc.):
- Sign in to the Advanced security options page of the Microsoft account (from a browser).
- Make sure at least one other security method is available on the account (for example, SMS, alternate email, or a new Authenticator registration). If not, add a new method first.
- In Advanced security options, locate the verification method associated with the old Authenticator app (for example, “Authenticator app” or the old device).
- Expand that verification option and select Remove.
- Select Remove again to confirm.
Important notes:
- Old security info does not need to be removed unless there is a security risk (for example, someone else has access to that phone or mailbox).
- If all security information is removed, the account goes into a restricted state for 30 days. During this period, security and billing settings cannot be changed, but email, Skype, OneDrive, and devices can still be used.
For a work or school (Entra ID / Microsoft 365) account:
- Go to https://aka.ms/mysecurityinfo in a browser and sign in.
- In Security info, delete the Authenticator app sign-in method that corresponds to the old phone.
- If unable to sign in because Authenticator is the only method, an administrator must reset MFA or require re-registration:
- An admin goes to Microsoft Entra ID in the Azure portal → Users → select the user → Authentication methods → Require re-register multifactor authentication.
- After this, sign-in will prompt to set up Authenticator again on a new device.
If the Authenticator app was configured as a passwordless sign-in method and deleting it is blocked, set up another two-factor method (such as SMS or phone call) first, then use that method to sign in and delete the passwordless Authenticator registration.
References:
- Removing a sign-in verification method
- Microsoft Authenticator FAQs
- Can't set up MFA because five devices are already registered to use an authenticator app
- Troubleshoot signing in with a passkey
- I cant log in to my business account because it is requiring Authenticator app which I do not have - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- Microsoft Authenticator app doesn't show 6-digit OTP code - Microsoft Q&A
- Having problems getting text codes to confirm my account - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A