A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Because the old phone cannot be used for MFA, the sign-in methods must be updated or reset before a new device can be added.
For a work or school (Microsoft Entra / Azure AD) account:
- If another admin exists in the tenant
- Ask another cloud services/global admin in the tenant to reset the MFA settings for the account:
- They sign in to the cloud service portal as admin.
- Go to
https://account.activedirectory.windowsazure.com/usermanagement/multifactorverification.aspx. - Select the checkbox for the affected user account.
- Select Manage user settings.
- Select Require selected users to provide contact methods again, then Save.
- After this, sign in again; the portal will prompt to set up MFA from scratch on the new phone (e.g., Microsoft Authenticator, phone number).
- Ask another cloud services/global admin in the tenant to reset the MFA settings for the account:
- If no other admin exists and this is the only global admin
- This is a tenant lockout scenario. Microsoft’s Data Protection team must help restore access.
- Contact Microsoft support by phone (Customer service phone numbers - Microsoft Support) and clearly state that access to the global admin account is blocked due to MFA and there is no other admin.
- The Data Protection team will verify identity and reset access/MFA so that MFA methods can be reconfigured on the new device.
- If the issue is only that the phone number or device changed but sign-in is still possible via another method
- After signing in, go to the Additional security verification / Security info page (
https://account.activedirectory.windowsazure.com/proofup.aspx?proofup=1). - Remove the old phone entry ("Security info type, phone, delete phone").
- Use Add sign-in method → choose Phone or Authenticator app and follow the prompts to register the new phone.
- After signing in, go to the Additional security verification / Security info page (
If the account is a personal Microsoft account (Hotmail/Outlook) and not an Azure AD work/school account, use the personal account security options and two-step verification management described in the MFA troubleshooting article to regain access and then update security info to the new phone.
References:
- Can't use Azure Multi-Factor Authentication to sign in to cloud services after you lose your phone or the phone number changes
- Use a screen reader to set up and troubleshoot multifactor authentication
- "We didn't receive a response" error message when you try to sign in by using Azure Multi-Factor Authentication
- I need to reset my mfa methods - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Azure has blocked myphone number for SMS verification due to a “bad reputation” flag - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A