A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
The accounts are locked in an MFA loop because the old Authenticator registration on the previous phone is still what Microsoft trusts, and there is no working alternative verification method. This cannot be fixed from the app alone; the MFA registration must be reset from the account side.
Use the path that matches each account type:
- For the school account (work or school / Entra ID account)
- If there is an IT/help desk at the school:
- Contact the school’s IT/help desk and explain that the phone was changed and the Microsoft Authenticator app no longer works.
- Ask them to reset the multifactor authentication (MFA) / two-step verification settings for the account in the Microsoft Entra admin center.
- After they reset MFA, sign in again; you will be prompted to set up Authenticator from scratch on the new phone.
- If there is no alternative method and sign-in keeps failing:
- The admin must investigate and reset MFA; end users cannot bypass this themselves. If sign-in attempts have been repeated many times, Microsoft Entra MFA may temporarily block additional attempts; in that case, wait and then try again after the admin reset.
- For the work account (business / organization account)
- If there is an administrator other than the affected user:
- Ask the organization’s Microsoft 365/Entra administrator to sign in to the Microsoft Entra admin center.
- They should go to Users → All users → select the user → Authentication methods and choose the option to require re-register multifactor authentication (or otherwise reset MFA methods).
- After this, sign in again and complete the new Authenticator setup on the new phone.
- If the affected user is the only administrator for the tenant:
- Contact Microsoft support by phone using the regional number listed under “Customer service phone numbers - Microsoft Support”.
- When the automated system asks, clearly indicate this is an Authenticator/MFA problem for an Office 365 for business/company account, that this is the administrator account, and that there are no other admins.
- Ask the agent to create a service request with the Microsoft Data Protection team to reset the MFA settings for the tenant admin account.
- Follow their identity-verification process; once verified, they can reset MFA so the account can be re-registered in Authenticator on the new phone.
- If codes or SMS/email verification are not arriving
- Avoid repeated sign-in attempts and repeated code requests; too many attempts can trigger temporary protection blocks where codes are not sent or sign-in is blocked.
- If “I can’t sign in after multiple attempts” appears, wait before trying again or use a different MFA method if one exists.
- If still stuck after admin/Data Protection reset attempts
- For work/school accounts, if all documented steps have been tried and the loop persists, the only supported path is continued work with the organization’s admin and, if necessary, Microsoft support/Data Protection until MFA is fully reset.
References:
- Common problems with two-step verification for a work or school account
- Microsoft Authenticator app doesn't show 6-digit OTP code - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- How Do I Regain Access to My Account After Losing Access to Microsoft Authenticator? (Urgent Request). - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A