A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
For a business (work or school) account where Microsoft Authenticator is the primary MFA method and SMS is failing with an error, recovery depends on whether there is another admin who can reset MFA for the account.
- Since SMS verification is failing and no email option is shown, use any other verification method that may already be configured:
- On the sign-in screen, choose Other verification options and try any alternative method that appears (for example, another phone number). Also verify that the phone numbers in the account are correct.
- If that does not work, the account may be blocked for MFA:
- A global admin must check whether the account is blocked from sign-in or MFA. In Microsoft Entra ID, they can:
- Go to the Azure portal → Microsoft Entra ID.
- Go to Users, open the affected user.
- Check Block sign in and disable it if enabled.
- From the user’s Authentication methods, reset/re-register MFA so the sign-in wizard lets the account be set up again on the new phone.
- A global admin must check whether the account is blocked from sign-in or MFA. In Microsoft Entra ID, they can:
- If there is another global admin in the tenant:
- Ask that admin to reset MFA for the account in the Microsoft Entra admin center (require re-register MFA and confirm phone numbers), then sign in again and set up Authenticator on the new phone.
- If there is no other global admin and this is the only admin account:
- This is a tenant lockout scenario. Only Microsoft’s Data Protection team can restore access.
- Use the global customer service phone numbers for Microsoft Support and clearly state:
- This is an Office 365/Microsoft 365 for business account.
- It is a company (work) account.
- The caller is the only administrator and is locked out due to Authenticator/MFA.
- Ask the agent to open a service request and route it to the Data Protection team to reset the admin’s authentication methods.
- If direct phone support cannot be reached, create a temporary trial Microsoft 365 tenant, go to the admin center of that trial tenant, and open a support ticket from there explaining that the real (locked) tenant’s only admin is locked out and needs Data Protection assistance.
- If this is not an admin account (regular user in an organization):
- Contact the organization’s Microsoft 365/Entra administrator and ask them to reset MFA for the account in the Entra admin center. After they do so, sign in again and reconfigure Authenticator on the new phone.
- While still signed in on the existing computer session:
- If the account has access to its own security settings (for example, via Security info / Additional security verification pages), use that signed-in session to:
- Add a new phone method (different number if the current one is blocked).
- Add or confirm an email method if allowed.
- Then sign out and test sign-in again with the new method.
- If the account has access to its own security settings (for example, via Security info / Additional security verification pages), use that signed-in session to:
If none of the above is possible and there is no admin who can reset MFA, the only supported path is through Microsoft Support/Data Protection as described.
References:
- You don't receive a text or voice call that contains the verification code for Microsoft Entra multifactor authentication
- Troubleshoot Microsoft verification code issues
- Common problems with two-step verification for a work or school account
- Use a screen reader to set up and troubleshoot multifactor authentication
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A