The personal Microsoft account is almost certainly a guest or member in an Azure AD (Microsoft Entra ID) tenant and has an Azure MFA profile there that is misconfigured (tenant expects 6‑digit codes, Authenticator is issuing 8‑digit codes). This causes the wrong MFA flow and blocks access.
From the available information, the working pattern to fix this is:
- Sign in to the affected tenant with another account that has Global Administrator rights.
- Use that admin account to reset MFA for the personal account in the tenant.
- After MFA is reset, sign in again with the personal account and complete a fresh MFA registration so the correct method is used.
Concretely, the admin in that tenant must:
- Go to the Microsoft Entra admin center.
- Navigate to Identity → Users → All users.
- Select the affected personal account (which appears as a guest or member user).
- Open Authentication methods for that user.
- Select Require re‑register MFA.
After this, the next sign‑in of the personal account to Azure will prompt for MFA registration again, allowing configuration of a compatible method and breaking the loop.
If there is no other Global Administrator in the tenant (or the only admin is locked out), this becomes a tenant lockout scenario. In that case, a support ticket with Microsoft is required so the Data Protection team can reset MFA or restore access, as described for similar lockout cases in the context.
If the tenant itself is blocked or inaccessible (for example, due to inactivity), the tenant administrator must contact Microsoft using the global support phone numbers to request reactivation before MFA or directory membership can be corrected.
Once MFA is reset and access is restored, the personal account can either:
- Remain as a guest in the tenant with a working MFA configuration, or
- Be removed from that tenant by an admin if it is no longer needed, so Azure no longer routes sign‑in through that directory.
References: