A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
For a personal Outlook.com account with two-step verification turned on and no working MFA methods, self-service recovery is not possible once all verification options are blocked by Microsoft Authenticator.
Based on the described situation:
- Two-step verification is enabled.
- The Microsoft Authenticator app on the old phone is no longer available.
- The new phone’s Authenticator cannot be set up because sign-in is blocked by MFA.
- Password reset flows always end by asking for Authenticator approval.
- The account recovery form is rejected for accounts with two-step verification enabled.
Microsoft’s documented behavior is:
- If two-step verification is turned on and none of the alternate verification methods are accessible, support agents cannot override or bypass MFA, reset the password, or change security details.
- The account recovery form cannot be used to bypass two-step verification.
The only supported options are:
- Use an existing, working MFA method (such as the original Authenticator app, a registered phone, or email/security info that still works) to complete sign-in or password reset.
- If no MFA method is accessible and two-step verification is enabled, the account cannot be recovered or unlocked by support.
If any of the following are still available, they must be used as the path back in:
- A previously configured alternate phone or email that still receives verification codes and is accepted without then requiring Authenticator.
- A device or browser where the account is still signed in and can access Security settings to change or remove MFA methods.
If none of these exist and every flow ends by demanding Microsoft Authenticator approval, the account is effectively unrecoverable under Microsoft’s security rules.
References: