A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Henry’s account MFA settings must be reset by an administrator or by Microsoft support; it can’t be reset from the locked account itself.
Based on the described behavior (Azure sign-in asking for a 6‑digit code while Microsoft Authenticator shows 8‑digit codes), the MFA registration is likely in a bad state and needs to be cleared so a fresh registration can be done.
Use the appropriate path below depending on whether there is another admin in the tenant.
- If there is another Global/Authentication Administrator in the tenant
Ask that admin to reset the MFA registration for the affected account:
- The admin signs in to the Microsoft Entra admin center.
- Go to Entra ID → Users → select the affected user.
- Open Authentication methods.
- Select Require re-register MFA.
This action:
- Deletes existing phone numbers, Microsoft Authenticator registrations, and software OATH tokens for that user.
- Forces the user to set up MFA again at next sign-in, where a correct method (push, 6‑digit OTP, phone, etc.) can be registered.
If the account is a guest in another tenant (for example, a personal Microsoft account added as a guest):
- A Global Admin in that tenant must perform the same Require re-register MFA on the guest user object.
- If there is no other admin and this is the only Global Admin account
In this case, self-service reset is not possible. Recovery must go through Microsoft support / Data Protection:
- Call Microsoft’s global customer service phone number for the region (see Customer service phone numbers - Microsoft Support in the references).
- When connected to the IVR/agent, clearly state:
- This is an Azure/Microsoft 365 for business / company account.
- The caller is the only administrator and is locked out due to Microsoft Authenticator / MFA.
- A request is needed for the Data Protection / Tenant Recovery team to reset MFA for the admin account.
- Follow the verification steps the Data Protection team requires to prove ownership of the tenant and account.
If phone support is difficult to reach, one workaround used in similar cases is:
- Create a new trial Microsoft 365/Azure tenant (with a different account) just to gain access to an admin portal.
- From that new tenant’s admin portal, open a support ticket requesting help from the Data Protection team to reset MFA on the original tenant where the admin is locked out.
- After MFA is reset
Once Require re-register MFA or a Data Protection reset is completed:
- Sign in again with username and password.
- When prompted to set up MFA, choose a method and complete registration:
- Microsoft Authenticator push notifications and/or 6‑digit OTP codes.
- Phone call or SMS as backup.
- Optionally add at least one alternative MFA method (for example, phone or another app) to avoid lockout if the primary device is lost.
References:
- Manage user authentication methods for Microsoft Entra multifactor authentication
- Reset Personal Azure MFA - Microsoft Q&A
- I need to reset my mfa methods - Microsoft Q&A
- Global Admin Locked out - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Microsoft Authenticator app doesn't show 6-digit OTP code - Microsoft Q&A