A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Yes. Recovery is possible, but it depends on whether any other verification methods or devices are still usable and whether this is a personal Microsoft account or a work/school tenant where support can intervene.
Follow these steps in order:
- Wait for the temporary lockout to clear
- The message about too many attempts indicates a temporary lock. During this period, alternative methods may also be blocked.
- Wait the full lockout period (often up to 24 hours) before trying again. Do not keep retrying during this time, as that can extend the lock.
- Try other verification methods (if configured)
- If any other methods were set up (SMS, alternate email, passkey, etc.), use those instead of Authenticator once the lockout clears.
- For a personal Microsoft account, if the Authenticator app is unavailable, any other configured method can be used. If Two Step Verification is turned on, two recovery methods are required to complete sign-in.
- If a passwordless sign-in was enabled and this is blocking access, a password can be added back after access is regained (see step 4).
- If the old phone still exists, check for an active Authenticator
- If the old device still powers on at all, open Microsoft Authenticator there and approve a sign-in. Notifications may still be going to that device instead of the new one.
- After signing in, remove the old device’s Authenticator entry from the account security settings so future prompts go only to the new phone.
- If passwordless is enabled, re-enable password sign-in (after access is regained)
- Once signed in by any method, go to the Microsoft account Additional security options page.
- Under “Passwordless account”, select Turn off and then Next.
- Follow the prompts to add a password back to the account so future sign-ins are not blocked by Authenticator-only flows.
- If no methods work and this is a work/school (tenant) account
- If this is a Microsoft 365 business/education account and there is at least one other global admin, that admin can reset MFA for the locked-out account.
- If there is only one global admin and that admin is locked out, the Microsoft Data Protection team must be engaged via a support ticket raised through Microsoft support. Frontline support escalates to Data Protection, who verify identity and reset MFA methods.
- If no methods work and this is a personal Microsoft account
- If no recovery method is accessible and the account is fully locked behind Authenticator, the only path is to use Microsoft’s account recovery and support process. The lockout must clear first; then the recovery form or support can be used to verify identity and regain access.
Once access is restored on the new phone:
- Remove any old passkeys or Authenticator-based sign-in methods that no longer apply.
- Add multiple recovery methods (Authenticator on the new device, SMS, alternate email, and optionally a password) so a single device failure does not cause lockout again.
References:
- How to go passwordless with your Microsoft account
- Troubleshoot signing in with a passkey
- Microsoft Authenticator FAQs
- Troubleshoot problems with Microsoft Authenticator
- How Do I Regain Access to My Account After Losing Access to Microsoft Authenticator? (Urgent Request). - Microsoft Q&A
- Cannot authenticate with E-mail when logging into Microsoft Authenticator(iOS). - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A