Locked out of Authenticator

Jayden Giles 0 Reputation points
2026-04-21T15:52:23.5833333+00:00

When I got a new phone I can’t log in to my authenticator on it. I try logging into it with my email and it says to authenticate with the app I’m trying to log into with. Then I press I can’t use my authenticator right now, and it ask me to type the pin shown on the authenticator app.

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Newest
  1. AI answer

    2026-04-21T15:52:39.5333333+00:00

    Because the account is protected by Microsoft Authenticator and the old phone is no longer available, the sign-in is stuck in a loop asking for a method that cannot be used.

    Use one of these recovery paths, depending on the account type and admin situation:

    1. If there is another admin on the tenant (work/school account)
      • Ask a Global Admin to reset the MFA methods for the account ("Require re-register MFA"), so new methods (new Authenticator, phone, etc.) can be configured. After reset, sign in again and set up Microsoft Authenticator on the new phone.
    2. If this is a personal Microsoft account and 2FA still has other working methods
      • On the sign-in screen, choose “I don’t have any of those” only if all configured methods are truly unusable. This starts the account recovery flow, where identity is verified and security info can be reset. Be aware this may remove existing MFA methods and require setting them up again.
    3. If this is the only admin on a business tenant and no other MFA method works
      • This is a tenant lockout scenario. The Microsoft Data Protection team must verify identity and reset access.
      • Call Microsoft Support using the country-specific number from Customer service phone numbers - Microsoft Support.
      • In the IVR/with the agent, clearly state:
        • The issue is with “Authenticator” for “Office 365 for business/company account”.
        • The caller is the only administrator.
        • A service request is needed with the Data Protection team to reset MFA for the global admin.
      • Alternatively, if normal support channels cannot be reached, create a temporary trial Microsoft 365 tenant, go to the new tenant’s admin center, and open a support ticket requesting the Data Protection team to help regain access to the original tenant.
    4. If still signed in on another device (e.g., Windows PC or browser)
      • While access is still available, update security info immediately:
        • Add an additional MFA method (phone, alternate email, or new Authenticator registration).
        • Remove the old, unusable Authenticator registration.
      • Then sign in on the new phone and set up Microsoft Authenticator again.

    If none of the above is possible and there is no other admin, the only supported path is working with Microsoft Support/Data Protection to verify identity and reset MFA.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.