A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Because the device with Microsoft Authenticator is lost, multifactor authentication (MFA) must be reset or an alternative sign-in method must be used before access to the directory and subscriptions can be restored.
Use the path that matches the situation:
- If there is another admin in the tenant
- Ask another cloud/global admin to sign in to the portal.
- They must open the MFA user management page:
- Select the affected account.
- Select Manage user settings.
- Check Require selected users to provide contact methods again, then select Save.
- Next sign-in will prompt to re-register MFA (add Authenticator on a new device and/or phone number). After that, directory and subscriptions will be accessible again.
- Go to Microsoft Entra admin center → Users → All users → select the user → Authentication methods → Require re-register multifactor authentication. This forces MFA re-registration on next sign-in.
- If there is an alternative MFA method already configured
- On the sign-in page, after entering username and password, when prompted for verification, use the Sign in another way link.
- Choose another method (for example, office phone, SMS, or other configured method) and complete sign-in.
- After signing in, update MFA methods and register the new Authenticator device.
- If there is no other admin and no alternative method
- For a work/school (Microsoft Entra ID / Microsoft 365 business) account where the locked-out user is the only admin:
- Contact Microsoft support by phone and request the Microsoft Data Protection team to help regain access and reset MFA for the tenant admin. Use the regional Customer service phone numbers listed in the documentation and clearly state that this is a tenant admin MFA lockout and that there is no other administrator.
- If the subscription is through a partner/reseller, contact the partner and ask them to open a service request with Microsoft on behalf of the tenant to reset the admin’s MFA.
- For a work/school (Microsoft Entra ID / Microsoft 365 business) account where the locked-out user is the only admin:
- If the device was lost or stolen
- Inform the organization’s help desk or admin so they can clear MFA settings for the account. After settings are cleared, the next sign-in will prompt for MFA registration again on the new device.
Until MFA is reset or an alternative method is used, access to the directory and its subscriptions/resources will remain blocked.
References:
- Can't use Azure Multi-Factor Authentication to sign in to cloud services after you lose your phone or the phone number changes
- Use a screen reader to set up and troubleshoot multifactor authentication
- Common problems with two-step verification for a work or school account
- I need to reset my mfa methods - Microsoft Q&A
- I cant log in to my business account because it is requiring Authenticator app which I do not have - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A