A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
If the Microsoft Authenticator entry for the account was deleted and there is no alternate MFA method configured, the account cannot be verified through the app and must be recovered using other available methods or with admin/support help.
Use the appropriate path based on the type of account:
- Work or school (Microsoft Entra / Microsoft 365) account
- If there is another MFA method configured (phone call, SMS, office phone):
- On the sign-in page, after entering username and password, choose Sign in another way.
- Select the alternative method (for example, phone or SMS) and complete verification.
- Go to the security info page (for example, via https://aka.ms/mysecurityinfo) and remove the old Authenticator method, then add the app again on the new device.
- If there is no alternative method and an administrator is available:
- Ask the Microsoft 365/Entra administrator to sign in to the Azure portal (https://portal.azure.com).
- Go to Microsoft Entra ID → Users → select the affected user.
- Open Authentication methods and select Require re-register multifactor authentication.
- Next sign-in will prompt to set up Authenticator again.
- If there is no other admin and the locked-out user is the only global admin:
- A Microsoft support/Data Protection (tenant recovery) case is required. The usual pattern from similar cases is:
- Call Microsoft support using the regional customer service phone number.
- Clearly state that this is a tenant lockout / global admin locked out due to MFA with no alternative methods.
- The frontline agent escalates to the Data Protection team, who verify tenant ownership and reset MFA registration so that at least one admin can sign in and add additional methods.
- A Microsoft support/Data Protection (tenant recovery) case is required. The usual pattern from similar cases is:
- Personal Microsoft account
- If another verification method (email, SMS, etc.) is configured, use Sign in another way on the sign-in screen and complete verification with that method, then update security info and re-add Authenticator.
- If no other method works and access is fully lost, follow the account recovery options presented on the sign-in/security pages; if recovery fails, direct support escalation is required, as community moderators cannot reset personal account security.
If repeated sign-in attempts have already been made, Microsoft Entra MFA may temporarily block further attempts; waiting and then trying a different MFA method (if available) is recommended.
References:
- Sign in using Microsoft Authenticator
- Authenticator Did Not Complete Login
- Can't set up MFA because five devices are already registered to use an authenticator app
- Authentication methods in Microsoft Entra ID - Microsoft Authenticator app
- Use a screen reader to set up and troubleshoot multifactor authentication
- Common problems with two-step verification for a work or school account
- How Do I Regain Access to My Account After Losing Access to Microsoft Authenticator? (Urgent Request). - Microsoft Q&A
- Cannot authenticate with E-mail when logging into Microsoft Authenticator(iOS). - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- Global Admin Locked out - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A