A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Because the phone was reset and the Microsoft Authenticator data is gone, recovery depends on how the account backup and security info were set up.
- If Authenticator cloud backup cannot be restored
- If the Authenticator backup account (the Microsoft account used for backup) cannot be accessed, support cannot restore Authenticator data.
- Use the Microsoft account sign-in helper to regain access to the Microsoft backup account: Sign-in helper.
- If backup still cannot be used, each account that was in Authenticator must be added again manually following the site’s or service’s MFA setup process.
- If the old phone number is still showing
- When trying to verify identity and an old phone number appears, use the “I don’t have any of these” or similar option on the verification screen (if shown). This starts the account recovery flow so security info can be updated.
- If the email address is correct but the phone/email security info is wrong or unfamiliar, use the account recovery process: recover your account.
- If only email is available and SMS/Auth app cannot be used
- If there is no access to the phone number or Authenticator, and only email works, choose the email method wherever possible to complete sign-in.
- If prompted to update backup security info and none of the listed methods are accessible, select I don't have any of these and follow the prompts to add new security info. Note that changing all security info at once can cause a temporary restriction period.
- When Authenticator accounts show “Action required” after restore
- If any accounts did restore but show Action required, open Authenticator, tap the affected account, then choose the option to sign in to recover. Enter the password and confirm the email or phone as requested.
- For work or school accounts with MFA lockout
- If this is a work or school account and access is blocked because of MFA, a global admin in the tenant can use Require re-register MFA for the user so MFA methods can be set up again.
- If there is only one admin and that admin is locked out, a support ticket with Microsoft (Data Protection team) is required to reset MFA and restore access.
If none of the available verification methods (phone, email, Authenticator) can be used and the account recovery flow cannot be completed, the account cannot be recovered through normal self-service and direct Microsoft support escalation is required for work/school tenants. For personal Microsoft accounts, recovery must be completed through the online account recovery process only.
References:
- Restore account credentials from Microsoft Authenticator
- Use a screen reader to set up and troubleshoot multifactor authentication
- Common problems with two-step verification for a work or school account
- Microsoft Authenticator FAQs
- I need to reset my mfa methods - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Azure has blocked myphone number for SMS verification due to a “bad reputation” flag - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- Keeps prompting "Add a recovery phone number" but my phone is already added for recovery - Microsoft Q&A