A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
To regain access to the admin account and reset Microsoft Authenticator, the available options depend on whether this is a work/school (tenant) account and whether there is another administrator.
- If this is a work or school (Microsoft Entra / Microsoft 365) account and there is another admin:
- Another cloud services admin must reset the Multi-Factor Authentication (MFA) settings:
- Sign in to the cloud service portal as an admin.
- Go to
https://account.activedirectory.windowsazure.com/usermanagement/multifactorverification.aspx. - Select the affected admin account.
- Select Manage user settings.
- Select Require selected users to provide contact methods again, then Save.
- Alternatively, in the Microsoft Entra admin center, an admin can:
- Go to Identity → Users → All users.
- Select the affected user.
- Open Authentication methods.
- Select Require re-register multifactor authentication.
- After this reset, sign-in will prompt to set up Authenticator again on the device.
- Another cloud services admin must reset the Multi-Factor Authentication (MFA) settings:
- If this is a work or school account and there is no other admin (you are the only Global Admin):
- Microsoft’s Data Protection team must assist with admin account recovery.
- Call Microsoft global customer service and request a ticket with the Data Protection team (describe that you are the only tenant admin locked out due to Authenticator/MFA). Use the flow described in the context (answer the IVR with “Authenticator”, “Office 365 for business”, “company account”, “Yes” for administrator, “No” for other admins, then request a service request).
- If direct phone support is difficult to reach, create a temporary trial tenant (Microsoft 365 trial), sign in to its admin center, and open a support ticket from there explicitly for the locked original tenant, providing the locked tenant’s domain, admin UPN, and error details. Data Protection will then work with you to verify identity and reset MFA on the original tenant.
- If this is a personal Microsoft account using Authenticator backup:
- If Authenticator backup cannot be restored and there is no access to the backup account, support cannot restore Authenticator credentials. Use the Microsoft account sign-in helper to regain access to the Microsoft account itself, then re-add accounts to Authenticator following the documented steps.
- If repeated sign-in attempts have been made:
- Microsoft Entra MFA may temporarily block sign-in after many attempts. Wait and try again later or use a different MFA method if one is configured. If this is a work/school account, an IT admin should review Entra sign-in logs and MFA configuration.
Since there is already an open support case, continue working with Microsoft Support on that case; if locked out as the only admin, explicitly request escalation to the Data Protection team for an admin MFA reset as outlined above.
References:
- Can't use Azure Multi-Factor Authentication to sign in to cloud services after you lose your phone or the phone number changes
- How to add your accounts to Microsoft Authenticator
- Common problems with two-step verification for a work or school account
- Restore account credentials from Microsoft Authenticator
- I need to reset my mfa methods - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- Reset Personal Azure MFA - Microsoft Q&A
- Authenticator Did Not Complete Login