A cloud-based identity and access management service for securing user authentication and resource access
The 8‑digit codes in Microsoft Authenticator indicate that the account is configured with an incompatible or stale MFA/sign‑in method for Azure Portal, even though it still works for other services. The Azure MFA profile for this account is likely stuck and must be reset from the tenant side so that new, correct methods (including 6‑digit codes or push notifications) can be registered.
Resolution requires an administrator in the tenant to reset the MFA registration for this user, then the user signs in again and reconfigures MFA:
- A Global Administrator (or another admin) signs in to the Microsoft Entra admin center.
- Go to Identity → Users → All users.
- Select the affected user account.
- Open Authentication methods.
- Select Require re-register multifactor authentication.
- Save the change.
After this, sign in to the Azure Portal again with the affected account. The sign‑in flow will prompt to set up MFA from scratch (for example, re‑adding Microsoft Authenticator or a phone method). This will register a fresh, compatible MFA configuration so that the correct verification options (including 6‑digit codes or push/prompt) are used for Azure sign‑in.
If the affected account is a guest in another tenant, an admin in that tenant must perform the same Require re-register multifactor authentication step on that guest user object.
If there is no other admin and this is the only admin account, create or use another admin account (as was done in the referenced scenario) to perform the reset, then reconfigure MFA for the original account.
References: