A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Error 399287 indicates that the phone number used for SMS verification has been blocked due to bad reputation or unusual activity, so Microsoft will not send verification codes to it.
For this situation, self-service fixes are not available; the block must be handled by Microsoft support/data protection.
Use these steps:
- Do not keep retrying SMS
- Repeated attempts can be treated as high-volume or unusual activity and extend or worsen the block.
- Try any other verification method on the account
- If another method is configured (alternate email, different phone, or Microsoft Authenticator that is still accessible on another device), use that to sign in and then update security info at the Security info page (for work/school accounts) to add a different mobile number.
- If no other method works, contact Microsoft support / Data Protection team
- For work or school accounts where the admin (or only admin) is locked out, Microsoft Data Protection has tools to verify identity and reset MFA or clear issues like this. Forum moderators and standard support channels cannot change MFA or send codes.
- Call the regional Microsoft support hotline and follow the automated prompts to open a service request for an Authenticator/MFA sign-in problem for an Office 365 for business (work account) tenant. Clearly state that:
- Sign-in fails at MFA with error code 399287.
- SMS verification is blocked and no other MFA method is usable.
- Access is needed to the work tenant to continue using services (such as Partner ID setup).
- If the tenant is from a partner/reseller and a global admin cannot open a ticket, ask the partner to open a service request on behalf of the tenant.
- Optional workaround to reach support if fully locked out
- If there is no way to sign in to the affected tenant to raise a ticket, create a separate temporary Microsoft 365 trial tenant, go to the Microsoft 365 admin center for that trial, and open a support ticket from there. In the ticket, specify that the real issue is with a different existing tenant where sign-in is blocked by MFA/SMS error 399287 and provide the tenant and admin details so Data Protection can work on that tenant.
Once Microsoft Data Protection verifies identity, they can reset MFA or otherwise clear the block so that sign-in can proceed and security methods can be updated.
If SMS codes still do not arrive after the block is resolved, use the guidance in the verification-code troubleshooting articles (for example, avoiding VOIP numbers, checking for unusual activity blocks, and waiting out temporary blocks) and consider switching to Microsoft Authenticator as the primary method, with a different mobile number or email as backup.
References:
- Common problems with two-step verification for a work or school account
- Troubleshoot Microsoft verification code issues
- 399287 - Microsoft Q&A Unable to Verify Identity for Azure Login – Error 399287
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Cannot authenticate with E-mail when logging into Microsoft Authenticator(iOS). - Microsoft Q&A
- Having problems getting text codes to confirm my account - Microsoft Q&A
- Azure has blocked myphone number for SMS verification due to a “bad reputation” flag - Microsoft Q&A