A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
For this situation, the account’s Azure MFA registration needs to be reset by an administrator or by Microsoft support; local changes to the Authenticator or using other apps (such as Google Authenticator) will not fix a stuck or mismatched MFA profile.
Use the path that matches the account type and admin situation:
- If there is another Global Administrator in the tenant
- Have that admin sign in to the Azure portal and open Microsoft Entra ID.
- Go to Identity > Users > All users.
- Select the affected user account.
- Open Authentication methods.
- Select Require re-register multifactor authentication.
- Sign in again with the affected account; it should now prompt to set up MFA from scratch (add Authenticator, phone, etc.).
- If the affected account is a guest in another tenant
- A Global Administrator in the resource tenant where the guest account is added must perform the same steps:
- Microsoft Entra admin center → Identity → Users → All users → [guest user] → Authentication methods → Require re-register MFA.
- After this, sign in again and complete MFA registration when prompted.
- A Global Administrator in the resource tenant where the guest account is added must perform the same steps:
- If the affected user is the only Global Administrator and is locked out
- Self-service reset is not possible from the portal in this state. A Data Protection/Tenant Recovery case with Microsoft Support is required so support can verify ownership and reset MFA on the admin account.
- If the phone or number was changed or lost
- Another cloud services admin can reset MFA contact methods using the legacy MFA management page:
- Sign in as admin.
- Go to
https://account.activedirectory.windowsazure.com/usermanagement/multifactorverification.aspx. - Select the affected user.
- Choose Manage user settings.
- Check Require selected users to provide contact methods again, then Save.
- The affected user then signs in and reconfigures MFA methods.
- Another cloud services admin can reset MFA contact methods using the legacy MFA management page:
If none of the above admins are available and the account is completely locked out, the only resolution path is escalation to Microsoft support (Data Protection/Tenant Recovery) through an existing admin or support channel associated with the tenant/subscription.
References:
- Troubleshoot Azure Multi-Factor Authentication issues
- Can't use Azure Multi-Factor Authentication to sign in to cloud services after you lose your phone or the phone number changes
- Can't set up MFA because five devices are already registered to use an authenticator app
- Reset Personal Azure MFA - Microsoft Q&A
- Global Admin Locked out - Microsoft Q&A
- I need to reset my mfa methods - Microsoft Q&A
- Azure has blocked myphone number for SMS verification due to a “bad reputation” flag - Microsoft Q&A
- Authenticator Did Not Complete Login