A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Because access to Microsoft Authenticator depends on the security info and backup account already configured, the next steps depend on what is still accessible.
- If the issue is restoring Authenticator accounts after the phone reset
- On the new phone, open Microsoft Authenticator.
- On Android, select Restore from backup (or Begin recovery) before signing in.
- Sign in using the same personal Microsoft account that was used as the Authenticator backup account. This restores the saved credentials.
- For any account that shows Sign in to restore your account or Action required, tap it and complete sign-in with the account password plus email/phone verification.
- If Restore from backup is not visible, remove or sign out of all accounts in Authenticator, then open it again and choose Restore from backup.
- If the backup account or security info cannot be accessed
- If Authenticator cannot restore because the backup Microsoft account (the one used for Authenticator backup) is not accessible, support cannot restore those credentials. Use the Microsoft account sign-in helper to regain access to that backup account: Sign-in helper.
- If still unable to restore, each account (personal, work/school, and third-party) must be added to Authenticator again using their own recovery or MFA reset process.
- If work or school accounts are locked behind MFA
- If the password is known but all security info (including Authenticator) is lost, begin sign-in to the work or school account, choose I don't have any of these at the “Verify your identity” step, and follow the prompts to replace security info. After replacement, sign-in will be blocked for 30 days until the change completes.
- If some security info still works (for example, another email or phone), sign in to Advanced security options, add a new way to sign in or verify, confirm it with a code, then remove the old methods that are no longer accessible.
- If the password is not known and no security info is accessible, use the Microsoft account recovery form as described in the documentation.
- If a business (tenant) account cannot be accessed and there is no alternative MFA method
- For a work or school account where Authenticator is the only MFA method and the device was reset, an administrator must reset MFA for that account in Microsoft Entra so MFA methods can be re-registered.
- If this is a business account and there is no other admin, contact Microsoft support by phone and request the Data Protection team to help with admin/MFA recovery, as described in the referenced guidance.
If none of the recovery options (backup account, alternate email/phone, or admin reset) are available, the only supported path is to recover each underlying Microsoft account (personal or work/school) using the official recovery flows, then re-add those accounts to Authenticator.
References:
- Restore account credentials from Microsoft Authenticator
- Common problems with two-step verification for a work or school account
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- I need to reset my mfa methods - Microsoft Q&A
- Can't sign in to my email - Microsoft Q&A
- Authenticator app not sending code to my email - Microsoft Q&A