Need to access the admin account to reset the authenticator

Murthala 0 Reputation points
2026-04-25T17:25:33.31+00:00

Hello,

I already have an ongoing case reference: 2604170030007171 related to this issue since 14/04/2026.

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Newest
  1. AI answer

    2026-04-25T17:25:49.9966667+00:00

    To regain access to the admin account and reset Microsoft Authenticator, the available options depend on whether this is a work/school (tenant) account and whether there is another administrator.

    1. If this is a work or school (Microsoft Entra / Microsoft 365) account and there is another admin:
      • Another cloud services admin must reset the Multi-Factor Authentication (MFA) settings:
        1. Sign in to the cloud service portal as an admin.
        2. Go to https://account.activedirectory.windowsazure.com/usermanagement/multifactorverification.aspx.
        3. Select the affected admin account.
        4. Select Manage user settings.
        5. Select Require selected users to provide contact methods again, then Save.
      • Alternatively, in the Microsoft Entra admin center, an admin can:
        1. Go to Identity → Users → All users.
        2. Select the affected user.
        3. Open Authentication methods.
        4. Select Require re-register multifactor authentication.
      • After this reset, sign-in will prompt to set up Authenticator again on the device.
    2. If this is a work or school account and there is no other admin (you are the only Global Admin):
      • Microsoft’s Data Protection team must assist with admin account recovery.
      • Call Microsoft global customer service and request a ticket with the Data Protection team (describe that you are the only tenant admin locked out due to Authenticator/MFA). Use the flow described in the context (answer the IVR with “Authenticator”, “Office 365 for business”, “company account”, “Yes” for administrator, “No” for other admins, then request a service request).
      • If direct phone support is difficult to reach, create a temporary trial tenant (Microsoft 365 trial), sign in to its admin center, and open a support ticket from there explicitly for the locked original tenant, providing the locked tenant’s domain, admin UPN, and error details. Data Protection will then work with you to verify identity and reset MFA on the original tenant.
    3. If this is a personal Microsoft account using Authenticator backup:
      • If Authenticator backup cannot be restored and there is no access to the backup account, support cannot restore Authenticator credentials. Use the Microsoft account sign-in helper to regain access to the Microsoft account itself, then re-add accounts to Authenticator following the documented steps.
    4. If repeated sign-in attempts have been made:
      • Microsoft Entra MFA may temporarily block sign-in after many attempts. Wait and try again later or use a different MFA method if one is configured. If this is a work/school account, an IT admin should review Entra sign-in logs and MFA configuration.

    Since there is already an open support case, continue working with Microsoft Support on that case; if locked out as the only admin, explicitly request escalation to the Data Protection team for an admin MFA reset as outlined above.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.