A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Because the old iPhone is gone and iCloud backup for Authenticator was not enabled, the app on the new iPhone cannot restore the previous accounts. The MFA loop happens because the sign-in is still requiring Microsoft Authenticator, but the configured Authenticator instance no longer exists.
The recovery options depend on what other sign-in methods are configured on the account and whether this is a personal account or a work/school (tenant) account.
- If this is a work or school account and there are other admins
- Ask another global/admin user in the organization to reset the MFA methods for the affected account in the admin portal.
- After the reset, sign in again and register Microsoft Authenticator on the new iPhone as a fresh MFA method.
- If this is a work or school account and there is only one admin (you)
- This is a tenant lockout scenario. The only supported path is to work with Microsoft’s Data Protection team via a support ticket.
- Call Microsoft Support using the country-specific number listed under “Customer service phone numbers - Microsoft Support” and clearly state:
- The issue is with Microsoft Authenticator and MFA.
- The product is Office 365/Microsoft 365 for business.
- It is a company (work) account.
- You are the only global admin and are locked out due to MFA.
- Ask the agent to create a service request and escalate to the Data Protection team to reset your MFA so you can regain access. Similar cases in the references were resolved this way after identity verification.
- If this is a personal Microsoft account and other methods exist
- On the sign-in screen, choose “I don’t have my Microsoft Authenticator app” or similar, then select another verification method (SMS/call/email) if it is offered.
- If SMS or call-based MFA is configured and the phone number is still active, use that to complete sign-in and then:
- Go to the account security page.
- Remove the old Authenticator method.
- Add Microsoft Authenticator again from the new iPhone.
- If this is a personal Microsoft account and no other methods work
- Use the “I don’t have any of these” or account recovery flow when prompted for MFA, and follow the on-screen steps to prove identity.
- If still unable to recover, contact Microsoft Support and request escalation for account recovery, explaining that all MFA methods point to an unavailable Authenticator instance.
- For future prevention once access is restored
- Enable backup for Microsoft Authenticator on iOS (iCloud Drive/Keychain/Backup) so accounts can be restored to a new device.
- Add at least one additional MFA method (SMS, call, alternate email, or another admin account for work tenants) so that loss of a phone does not cause a lockout.
References:
- Microsoft Authenticator FAQs
- Migrate to a new iPhone for work
- Troubleshoot problems with Microsoft Authenticator
- How Do I Regain Access to My Account After Losing Access to Microsoft Authenticator? (Urgent Request). - Microsoft Q&A
- Cannot authenticate with E-mail when logging into Microsoft Authenticator(iOS). - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A