Authenticator/MFA lockout with no alternative

Adam Bowie 0 Reputation points
2026-04-17T10:38:06.2766667+00:00

I've accidentally deleted my domain on Authenticator with no alternate sign in of authenticate my login. What do I do?

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-04-17T10:38:18.8466667+00:00

    If the Microsoft Authenticator entry for the account was deleted and there is no alternate MFA method configured, the account cannot be verified through the app and must be recovered using other available methods or with admin/support help.

    Use the appropriate path based on the type of account:

    1. Work or school (Microsoft Entra / Microsoft 365) account
    • If there is another MFA method configured (phone call, SMS, office phone):
      1. On the sign-in page, after entering username and password, choose Sign in another way.
      2. Select the alternative method (for example, phone or SMS) and complete verification.
      3. Go to the security info page (for example, via https://aka.ms/mysecurityinfo) and remove the old Authenticator method, then add the app again on the new device.
    • If there is no alternative method and an administrator is available:
      1. Ask the Microsoft 365/Entra administrator to sign in to the Azure portal (https://portal.azure.com).
      2. Go to Microsoft Entra IDUsers → select the affected user.
      3. Open Authentication methods and select Require re-register multifactor authentication.
      4. Next sign-in will prompt to set up Authenticator again.
    • If there is no other admin and the locked-out user is the only global admin:
      • A Microsoft support/Data Protection (tenant recovery) case is required. The usual pattern from similar cases is:
        • Call Microsoft support using the regional customer service phone number.
        • Clearly state that this is a tenant lockout / global admin locked out due to MFA with no alternative methods.
        • The frontline agent escalates to the Data Protection team, who verify tenant ownership and reset MFA registration so that at least one admin can sign in and add additional methods.
    1. Personal Microsoft account
    • If another verification method (email, SMS, etc.) is configured, use Sign in another way on the sign-in screen and complete verification with that method, then update security info and re-add Authenticator.
    • If no other method works and access is fully lost, follow the account recovery options presented on the sign-in/security pages; if recovery fails, direct support escalation is required, as community moderators cannot reset personal account security.

    If repeated sign-in attempts have already been made, Microsoft Entra MFA may temporarily block further attempts; waiting and then trying a different MFA method (if available) is recommended.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.