Locked out of authenticator app for business account

Juan Maldonado 0 Reputation points
2026-04-17T13:04:56.7433333+00:00

I switched phones and I didn't know I needed to use the old phone to get the code to set up the authentication for one of my accounts, when I try to do the option by text I get the following error:

Troubleshooting details

If you contact your administrator, send this info to them.

Copy info to clipboard

Error Code: 399287

Request Id: 701808b8-0a21-4ab9-8055-560844582700

Correlation Id: 64f8ef08-f8ef-4e5a-95dd-0a5d18b7a268

Timestamp: 2026-04-17T12:57:26Z

Flag sign-in errors for review: Enable flagging

If you plan on getting help for this problem, enable flagging and try to reproduce the error within 20 minutes. Flagged events make diagnostics available and are raised to admin attention.

Close troubleshooting details

From what I have been able to tell this seems to be a phone number flagged issue (I use it for multiple accounts) but I want to know if there is another way around this, I can't log into outlook or anything else outside of my computer (which thankfully stayed logged in), I don't even see an option to send a code to my email.

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-04-17T13:05:19.16+00:00

    For a business (work or school) account where Microsoft Authenticator is the primary MFA method and SMS is failing with an error, recovery depends on whether there is another admin who can reset MFA for the account.

    1. Since SMS verification is failing and no email option is shown, use any other verification method that may already be configured:
      • On the sign-in screen, choose Other verification options and try any alternative method that appears (for example, another phone number). Also verify that the phone numbers in the account are correct.
    2. If that does not work, the account may be blocked for MFA:
      • A global admin must check whether the account is blocked from sign-in or MFA. In Microsoft Entra ID, they can:
        1. Go to the Azure portalMicrosoft Entra ID.
        2. Go to Users, open the affected user.
        3. Check Block sign in and disable it if enabled.
        4. From the user’s Authentication methods, reset/re-register MFA so the sign-in wizard lets the account be set up again on the new phone.
    3. If there is another global admin in the tenant:
      • Ask that admin to reset MFA for the account in the Microsoft Entra admin center (require re-register MFA and confirm phone numbers), then sign in again and set up Authenticator on the new phone.
    4. If there is no other global admin and this is the only admin account:
      • This is a tenant lockout scenario. Only Microsoft’s Data Protection team can restore access.
      • Use the global customer service phone numbers for Microsoft Support and clearly state:
        • This is an Office 365/Microsoft 365 for business account.
        • It is a company (work) account.
        • The caller is the only administrator and is locked out due to Authenticator/MFA.
      • Ask the agent to open a service request and route it to the Data Protection team to reset the admin’s authentication methods.
      • If direct phone support cannot be reached, create a temporary trial Microsoft 365 tenant, go to the admin center of that trial tenant, and open a support ticket from there explaining that the real (locked) tenant’s only admin is locked out and needs Data Protection assistance.
    5. If this is not an admin account (regular user in an organization):
      • Contact the organization’s Microsoft 365/Entra administrator and ask them to reset MFA for the account in the Entra admin center. After they do so, sign in again and reconfigure Authenticator on the new phone.
    6. While still signed in on the existing computer session:
      • If the account has access to its own security settings (for example, via Security info / Additional security verification pages), use that signed-in session to:
        • Add a new phone method (different number if the current one is blocked).
        • Add or confirm an email method if allowed.
        • Then sign out and test sign-in again with the new method.

    If none of the above is possible and there is no admin who can reset MFA, the only supported path is through Microsoft Support/Data Protection as described.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.