A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
The authenticator requirement cannot be reset or removed directly by the end user. Resolution depends on whether the account is work/school (Microsoft Entra ID / Microsoft 365) or part of a Microsoft Advertising/Xandr product.
For a work or school (Microsoft Entra ID / Microsoft 365) account:
- If there is an administrator in the tenant
- Contact the organization’s Microsoft 365/Entra administrator and ask them to reset MFA by requiring re‑registration:
- Admin signs in to the Microsoft Entra admin center.
- Go to Identity → Users → All users.
- Select the affected user account.
- Open Authentication methods.
- Select Require re-register multifactor authentication.
- After this, sign in again; the account will be prompted to set up MFA (Authenticator, phone, etc.) from scratch.
- Contact the organization’s Microsoft 365/Entra administrator and ask them to reset MFA by requiring re‑registration:
- If the account is a business/organization account and there is no other admin
- If another global admin exists, ask them to perform the same Require re-register multifactor authentication action on the affected admin account.
- If the locked-out user is the only global admin, a new temporary admin account can be created (for example, via support or an additional tenant) and used to:
- Sign in to the Microsoft Entra admin center.
- Go to Identity → Users → All users.
- Select the locked-out user.
- Use Authentication methods → Require re-register multifactor authentication to reset MFA for that user.
- If no admin access is possible at all
- For business/organization tenants where the only admin is locked out, Microsoft’s Data Protection team must reset MFA after verifying identity. This is initiated by calling the regional support number listed under Customer service phone numbers - Microsoft Support and asking to open a ticket with the Data Protection team to reset MFA for the tenant admin.
For Microsoft Advertising / Xandr products (Curate, Monetize, Invest):
- If an MFA app (such as Auth0 Guardian, Google Authenticator, etc.) was deleted or is no longer accessible, the MFA profile must be reset by Product Support.
- Contact Product Support for the specific Microsoft Advertising/Xandr product and request an MFA reset for the affected user account so that MFA can be configured again.
Once an admin or support resets MFA, sign in again and follow the prompts to add Microsoft Authenticator or another MFA method properly.
References:
- How to add your accounts to Microsoft Authenticator
- Can't set up MFA because five devices are already registered to use an authenticator app
- Use a screen reader to set up and troubleshoot multifactor authentication
- Microsoft Curate - Troubleshoot Multi-Factor Authentication (MFA)
- Microsoft Monetize - Troubleshooting MFA
- Microsoft Invest - Troubleshoot Multi-Factor Authentication (MFA)
- I need to reset my mfa methods - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- Reset Personal Azure MFA - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Microsoft Authenticator app doesn't show 6-digit OTP code - Microsoft Q&A