A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Because sign-in is protected by Microsoft Authenticator, and access to the Authenticator app is currently blocked by the same prompt, use an alternate verification method or recovery path that does not depend on approving a notification in Authenticator.
Use these steps in order:
- Try another sign-in method
- On the sign-in screen where it says Open your Authenticator app and approve the request. Enter the number if prompted., select Other ways to sign in (or similar option shown).
- Choose one of the available alternatives, for example:
- Use a verification code from my mobile app (TOTP code instead of push notification).
- Text a code or Call my phone, if phone/SMS is configured.
- Then follow the flow described in:
- For app code: open the authenticator app (or other TOTP app) and enter the verification code from mobile app into the sign-in page.
- For SMS/phone: enter the code from the text message or follow the phone instructions.
- Sign in using an authenticator app notification or code.
- Sign in using your phone number or a text message.
- Use Outlook mobile / Authenticator Lite if available
- If Outlook mobile is installed and configured with the same account, it can act as an authenticator (Authenticator Lite).
- When prompted with “Are you trying to sign in?”, open Outlook mobile and approve the sign-in there.
- If any unrequested prompts appear, always select Deny.
- If no alternative method works and all devices are logged out
- If this is a personal Microsoft account (consumer):
- Go to the Microsoft account security page in a browser and use any available backup method (alternate email, SMS, or security info) to pass verification, then:
- Review and update Security info (add SMS, alternate email, or a security key so there is always a backup method).
- Optionally set up passwordless sign-in again only after confirming backup methods are working.
- Go to the Microsoft account security page in a browser and use any available backup method (alternate email, SMS, or security info) to pass verification, then:
- If this is a work or school account and there is no way past the Authenticator prompt:
- Contact the organization’s IT/admin and request an MFA reset or temporary bypass. Admins can clear the existing Authenticator registration so it can be set up again on the new device.
- If this is a personal Microsoft account (consumer):
- After access is restored, harden the account
- Ensure at least two verification methods are configured (for example, Authenticator app + SMS or security key) so that losing one device does not block sign-in.
- Consider enabling passwordless sign-in only after confirming that backup methods (SMS, alternate email, or security key) are working, as described in the passwordless guidance.
If this is a tenant/global admin account and there is no other admin who can reset MFA, a support ticket with Microsoft is required so the Data Protection team can help restore access.
References:
- Sign in using two-step verification or security info
- Authentication methods in Microsoft Entra ID - Microsoft Authenticator app
- How to go passwordless with your Microsoft account
- Using Outlook mobile to sign in
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A