A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
When Microsoft Authenticator is required and there is no access to it, recovery depends on whether this is a personal Microsoft account or a work/school (business) account, and on whether any other sign-in or verification methods are still available.
- If this is a personal Microsoft account (Outlook/Hotmail/Xbox, etc.)
- If two-step verification is turned on and none of the configured verification methods (Authenticator, phone, email, security key, etc.) are accessible, support cannot bypass this protection or remove Authenticator.
- In that case, the only supported path is:
- Use the Microsoft account sign-in helper to diagnose and guide recovery: Sign-in helper or Sign-in helper depending on entry point.
- If the normal reset flow fails and there is no access to any verification options, fill out the Microsoft account recovery form with as much accurate information as possible: Account recovery form.
- Important: If two-step verification is enabled and there is no access to any of the alternate verification methods, Microsoft support agents are not allowed to reset the password, remove 2FA, or change security details. In that situation the account cannot be recovered.
- If this is a work or school (business) account protected by Authenticator
- If there is another sign-in method configured (SMS, email code, security key), use that method to sign in instead of Authenticator.
- If this is a business account and there is an organization admin:
- Contact the organization’s IT/help desk and ask them to clear or reset the MFA settings in Microsoft Entra Admin Center so that sign-in can be completed and Authenticator can be set up again on the current device.
- If this is a business account and the only global admin has lost Authenticator access:
- Call Microsoft’s customer service phone number for the region (see “Customer service phone numbers” in the referenced Q&A answers) and explicitly request a ticket with the Data Protection team to reset the admin’s authentication methods.
- If reaching an agent is difficult, one documented workaround is to create a temporary trial Microsoft 365 tenant, sign in as that tenant’s admin, and open a support ticket from the Microsoft 365 Admin Center asking the Data Protection team to help with the original tenant’s admin MFA reset.
- If Authenticator backup cannot be restored
- If Authenticator credentials were not backed up, or the backup account itself is inaccessible, support cannot restore Authenticator data. In that case, accounts must be recovered individually using their own recovery methods, or re-added after access is regained.
- Why the “loop” happens
- The loop where email verification succeeds but the sign-in still demands Authenticator usually means:
- The account is configured with two-step verification/MFA where Authenticator is the required second factor, and
- The policy or configuration does not allow replacing that second factor with email alone for that scenario.
- Because of security policy, support cannot override this or send custom codes.
If none of the above paths (alternate verification method, organization admin reset, Data Protection escalation, or the account recovery form) are available or successful, the account cannot be recovered under Microsoft’s documented security rules.
References:
- Restore account credentials from Microsoft Authenticator
- Help with the Microsoft account recovery form
- Troubleshoot Microsoft verification code issues
- Common problems with two-step verification for a work or school account
- I cant log in to my business account because it is requiring Authenticator app which I do not have - Microsoft Q&A
- Can't sign in to my email - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- Having problems getting text codes to confirm my account - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A