A cloud-based identity and access management service for securing user authentication and resource access
For a personal Microsoft account used with Azure, there is no self-service way to reset a broken Azure MFA configuration if no verification method works. The issue must be resolved at the tenant level by an administrator or, if that is not possible, by Microsoft Support (Data Protection / Tenant Recovery).
Use the following approaches depending on how the account is used in Azure:
- If the account is a guest user in someone else’s Azure tenant
- Ask a Global Administrator in that tenant to reset MFA for the affected account:
- Sign in to the Microsoft Entra admin center as a Global Administrator.
- Go to Identity > Users > All users.
- Select the affected user.
- Open Authentication methods.
- Select Require re-register multifactor authentication.
- After this, sign in again; Azure will prompt to register MFA from scratch and new methods can be configured.
- Ask a Global Administrator in that tenant to reset MFA for the affected account:
- If there is another Global Administrator account in the tenant
- That admin can perform the same steps as above to force re-registration of MFA for the locked-out account:
- Sign in to Azure portal → Microsoft Entra ID.
- Users → select the locked-out user.
- Authentication methods → Require re-register multifactor authentication.
- On next sign-in, the account will be asked to set up MFA again.
- That admin can perform the same steps as above to force re-registration of MFA for the locked-out account:
- If the locked-out account is the only Global Administrator
- Self-service recovery is not possible when no MFA method works and there is no other Global Administrator.
- In this case, open a support case and request escalation to the Microsoft Data Protection / Tenant Recovery team so they can:
- Verify tenant ownership using contact details and proof of control.
- Reset or re-register MFA for at least one admin account.
- This process is similar to what other customers have described: support escalates to a duty manager, then to the Data Protection team, who verify identity and reset MFA so that access to the tenant can be restored.
- If the personal Microsoft account itself cannot be signed in anywhere
- If the problem is at the Microsoft account level (not just Azure tenant MFA), use the standard Microsoft account recovery flows:
- If the password is forgotten, use Reset your password.
- If the password is known but sign-in fails, use the Sign-in Helper tool.
- If verification codes are not working for the Microsoft account itself, follow the documented troubleshooting steps for verification code issues.
- If the problem is at the Microsoft account level (not just Azure tenant MFA), use the standard Microsoft account recovery flows:
Because push notifications and codes are not accepted and error 500121 indicates an MFA problem, recovery requires either:
- A tenant admin using Require re-register multifactor authentication on the user, or
- A Microsoft Support escalation (Data Protection / Tenant Recovery) if no admin can sign in.
References:
- Reset Personal Azure MFA - Microsoft Q&A
- How Do I Regain Access to My Account After Losing Access to Microsoft Authenticator? (Urgent Request). - Microsoft Q&A
- Global Admin Locked out - Microsoft Q&A
- Azure has blocked myphone number for SMS verification due to a “bad reputation” flag - Microsoft Q&A
- Can not access Azure - Microsoft Q&A
- I can't sign in to my Microsoft account
- "We didn't receive a response" error message when you try to sign in by using Azure Multi-Factor Authentication
- Use a screen reader to set up and troubleshoot multifactor authentication
- "We did not receive the expected response" error message when you try to sign in by using Azure Multi-Factor Authentication