A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
The account is locked in an MFA loop because all available verification methods are tied to Microsoft Authenticator on the old phone and there is no alternative method available outside the app.
In this situation, self-service recovery is not possible. The only supported way to regain access is to have the MFA methods reset by Microsoft support, specifically the Data Protection team, if there is no other administrator who can reset MFA.
Use the following approach, depending on the account type:
- If this is a work or school (Microsoft 365 business/education) account and there is at least one other admin in the tenant:
- Another global admin must sign in to the Microsoft 365 admin center and reset the MFA methods for the affected account so that new methods (including a fresh Authenticator registration) can be configured.
- If this is a work or school account and there is only one admin (the locked-out account):
- Contact Microsoft support by phone via the global customer service numbers and clearly state that this is an admin lockout due to Microsoft Authenticator and that there is no other administrator.
- Ask for a service request and escalation to the Data Protection team to perform an admin MFA reset. Be prepared to verify identity and tenant ownership with business documentation.
- If direct phone support cannot be reached, create a new temporary Microsoft 365 trial tenant, go to the admin center of that new tenant, and open a support ticket requesting the Data Protection team to help regain access to the original tenant, providing the locked tenant’s domain, admin UPN, and error details.
- If this is a personal Microsoft account and no other sign-in method (SMS, email, security key, etc.) is available outside Authenticator:
- Use the account recovery and password reset options provided for personal accounts and follow the prompts to prove identity using whatever alternative contact details are still on file. If all methods route back to Authenticator and cannot be used, support agents cannot override verification or send codes directly; recovery depends on the available self-service options.
Until at least one sign-in method that does not depend on the current Authenticator instance is added (for example SMS, email, or a new Authenticator registration), the loop will persist. The resolution is therefore to have MFA reset by an admin or, if none exists, by Microsoft’s Data Protection team after identity verification.
References:
- Troubleshoot problems with Microsoft Authenticator
- Microsoft Authenticator FAQs
- Common problems with two-step verification for a work or school account
- Authenticator Did Not Complete Login
- How Do I Regain Access to My Account After Losing Access to Microsoft Authenticator? (Urgent Request). - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Cannot authenticate with E-mail when logging into Microsoft Authenticator(iOS). - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A