In my authenticator app they state "sign in to add your account" if i try to sign in they want me to athenticate with my app where I am not signed in!

Michiel van der Meer 0 Reputation points
2026-04-02T06:09:05.2766667+00:00

In my authenticator app they state "sign in to add your account" if i try to sign in they want me to athenticate with my app where I am not signed in!

So this will never work. how to reset that?

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-04-02T06:18:41.49+00:00

    The loop happens because the account is already configured to require Microsoft Authenticator, but the app is not yet fully set up for that account. The reset is not done in the app itself; it must be done from the account side or by an administrator/support.

    The exact fix depends on whether this is a personal Microsoft account or a work/school account.


    1. Personal Microsoft account (Outlook.com, Hotmail, Xbox, etc.)

    For personal accounts, the supported way to break this loop is to add the account directly inside the Authenticator app, then complete the passwordless setup from the account page.

    Follow these steps:

    1. Install and open Microsoft Authenticator on the phone.
    2. In the app, tap + Add account.
    3. Choose the correct account type (for example, Personal account / Microsoft account).
    4. Tap Sign in with Microsoft.
    5. Enter the Microsoft account email and password.
    6. When asked to verify, use any other available method (for example, SMS code, email code, or another configured method). This step is critical: the app cannot verify itself; it needs an alternative method.
    7. After verification, the account is added properly to Authenticator.
    8. Then go to the Add a new way to sign in or verify page for the Microsoft account and choose Use an app to complete passwordless sign-in setup:
      • Open the browser and go to Add a new way to sign in or verify (as described in the article).
      • Select Use an app.
      • Click Get it now, then close the new window (the app is already installed).
      • Select Next, then Finish.

    This flow is described in the article for the error “You haven't finished yet” and is designed specifically for cases where passwordless sign-in is half-configured and the app is stuck.

    If there is no other verification method (no SMS, no email, no backup codes), then self-service recovery is not possible; support must reset the sign-in methods for the account.


    2. Work or school account (Microsoft 365 / Entra ID)

    For work or school accounts, the Authenticator requirement is controlled by the organization. The loop is broken by resetting MFA for the user in Microsoft Entra ID.

    There are three cases:

    a) There is another admin in the tenant

    Ask that admin to reset MFA for the account:

    1. The admin signs in to the Microsoft Entra admin center.
    2. Go to Identity → Users → All users.
    3. Select the affected user.
    4. Open Authentication methods.
    5. Click Require re-register multifactor authentication.
    6. Sign out and sign in again as the affected user. The next sign-in will prompt to set up Authenticator from scratch (scan QR code or sign in in the app). This breaks the loop because the old binding is cleared.

    This is the standard, documented way to reset MFA methods for a user.

    b) The user is an end-user (not admin) and cannot reach another admin

    In this case, only the organization’s IT/admin team can reset MFA. The user must:

    • Identify and contact the Microsoft 365 / IT administrator (for example, via internal helpdesk or the guidance in “How do I find my Microsoft 365 admin?” referenced in the Q&A).
    • Ask them explicitly to reset MFA / Require re-register multifactor authentication for the account.

    Forum moderators and general support cannot directly change MFA for business tenants; it must be done by an admin or via the Data Protection process.

    c) The user is the only global admin and is locked out

    If the account is the sole global administrator and is locked behind Authenticator, the only supported options are:

    1. Call Microsoft support and request the Data Protection team to reset MFA for the tenant admin:
      • Call the appropriate Customer service phone number.
      • Ignore the initial 30-second message and wait for menu options.
      • When prompted by the IVR, respond along these lines (as documented in the Q&A):
        • Problem: “Authenticator” or “lost account / can’t sign in with MFA”.
        • Product: “Office 365 for business”.
        • Type: “Company account”.
        • Are you an administrator? “Yes.”
        • Do you have another administrator? “No.”
        • Do you need a service request? “Yes, I need to speak with the Data Protection team to reset MFA for the only admin.”
      • The Data Protection team will verify identity and can revoke/reset the MFA methods for the admin account.
    2. If it is impossible to reach a live agent, create a temporary trial tenant as a workaround:
      • Sign up for a Microsoft 365 trial to create a new tenant.
      • Sign in to the Microsoft 365 admin center for that trial tenant.
      • Use Help & Support to open a support ticket.
      • In the ticket, request to speak with the Data Protection team on behalf of the original tenant and ask them to reset MFA for the locked admin account.
      • After the issue is resolved, cancel the trial to avoid charges.

    This process is described in multiple Q&A answers for cases where the only admin is locked out by Authenticator.


    3. When the app shows setup or registration errors

    If the app shows messages like:

    • “You haven't finished yet” when enabling passwordless sign-in, or
    • Errors about incomplete setup or blocked registration

    then:

    • For personal accounts, follow the direct add in app → Add a new way to sign in or verify → Use an app flow described above.
    • For work/school accounts, check if the admin has blocked registration or restricted locations (Conditional Access). In that case, the admin must adjust policies or explicitly allow Authenticator registration, as described in the setup error guidance.

    If the message is about restricted location or blocked registration, only the organization’s admin can change that; it cannot be fixed from the app.


    Key points to break the loop

    • The Authenticator app cannot verify itself; another method (SMS, email, backup code, or admin reset) is required.
    • For personal accounts, add the account directly in the app, then complete passwordless setup from the account’s security page.
    • For work/school accounts, an admin must use Require re-register multifactor authentication in Microsoft Entra, or the Data Protection team must reset MFA if no admin access is available.
    • If there is no alternative method and no admin/support involvement, the loop cannot be broken purely from within the app.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.