A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
The MFA methods on the account are registered to someone else’s phone and Microsoft Authenticator, so they must be reset by an administrator or support; self-service won’t work while those methods remain in place.
Use the appropriate path based on the type of account:
- Work or school (Microsoft Entra / Microsoft 365 business)
- If there is another administrator in the tenant:
- Ask that admin to sign in to the Microsoft Entra admin center.
- Go to Identity → Users → All users.
- Select the affected user account.
- Open Authentication methods.
- Select Require re-register multifactor authentication.
- After this, sign in again; the old phone/app will no longer be used and new MFA methods can be registered.
- If there is no other admin and this is the only global admin account:
- Contact Microsoft support by phone using the global customer service numbers and request the Data Protection/Tenant Recovery team to reset MFA for the tenant admin, explaining that the current MFA phone and Authenticator are not yours.
- If unable to open a ticket from the locked tenant, create a temporary trial tenant, use its admin center to open a support ticket, and ask support to help with MFA reset for the original tenant.
- If there is another administrator in the tenant:
- End user in an organization (not an admin)
- Contact the organization’s IT help desk or Microsoft 365 administrator.
- Ask them to reset MFA for the account by using Require re-register multifactor authentication in the Microsoft Entra admin center as above.
- If the account is a cloud-services admin (Azure, Intune, Office 365) and another admin exists
- Ask the other admin to:
- Sign in to the cloud service portal.
- Go to
https://account.activedirectory.windowsazure.com/usermanagement/multifactorverification.aspx. - Select the affected admin account.
- Choose Manage user settings.
- Select Require selected users to provide contact methods again, then Save.
- On next sign-in, MFA contact methods will be re-collected and can be set to the correct phone/app.
- Ask the other admin to:
If no alternative verification methods are configured and no admin is available to reset MFA, direct support from Microsoft (Data Protection team) is required; forum moderators and normal users cannot change MFA bindings.
References:
- Can't use Azure Multi-Factor Authentication to sign in to cloud services after you lose your phone or the phone number changes
- Use a screen reader to set up and troubleshoot multifactor authentication
- Common problems with two-step verification for a work or school account
- Can't set up MFA because five devices are already registered to use an authenticator app
- I need to reset my mfa methods - Microsoft Q&A
- Reset Personal Azure MFA - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Global Admin Locked out - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A