Unable to Access Azure Portal – MFA Not Sending Code to Authenticator App

kriera 0 Reputation points
2026-03-25T22:04:28.5866667+00:00

Hi, I'm trying to access Azure portal and it's impossible to do so.

I've removed the authenticator, added back, tried other phone. Azure portal is not allowing me to login unless I add the mfa code that is not sending, and neither accept the one authenticator is generating... can't even auth my identity by using the other email registered or requesting to recieve sms only authenticator app.

PS: I've also tried the google authenticator app adding it there with same results.

Please help.

I've readed the documentation tried all and still no success.

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Oldest
  1. AI answer

    2026-03-25T22:04:52.97+00:00

    For this situation, the account’s Azure MFA registration needs to be reset by an administrator or by Microsoft support; local changes to the Authenticator or using other apps (such as Google Authenticator) will not fix a stuck or mismatched MFA profile.

    Use the path that matches the account type and admin situation:

    1. If there is another Global Administrator in the tenant
      1. Have that admin sign in to the Azure portal and open Microsoft Entra ID.
      2. Go to Identity > Users > All users.
      3. Select the affected user account.
      4. Open Authentication methods.
      5. Select Require re-register multifactor authentication.
      6. Sign in again with the affected account; it should now prompt to set up MFA from scratch (add Authenticator, phone, etc.).
    2. If the affected account is a guest in another tenant
      1. A Global Administrator in the resource tenant where the guest account is added must perform the same steps:
        • Microsoft Entra admin center → Identity → Users → All users → [guest user] → Authentication methods → Require re-register MFA.
      2. After this, sign in again and complete MFA registration when prompted.
    3. If the affected user is the only Global Administrator and is locked out
      • Self-service reset is not possible from the portal in this state. A Data Protection/Tenant Recovery case with Microsoft Support is required so support can verify ownership and reset MFA on the admin account.
    4. If the phone or number was changed or lost
      • Another cloud services admin can reset MFA contact methods using the legacy MFA management page:
        1. Sign in as admin.
        2. Go to https://account.activedirectory.windowsazure.com/usermanagement/multifactorverification.aspx.
        3. Select the affected user.
        4. Choose Manage user settings.
        5. Check Require selected users to provide contact methods again, then Save.
      • The affected user then signs in and reconfigures MFA methods.

    If none of the above admins are available and the account is completely locked out, the only resolution path is escalation to Microsoft support (Data Protection/Tenant Recovery) through an existing admin or support channel associated with the tenant/subscription.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.