A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
The behavior matches a situation where Microsoft Authenticator on the old phone is still the “active” device, so approvals and registration flows are effectively tied to it instead of the new phone.
Use these steps and checks:
- Confirm which device is receiving prompts
- When registering or signing in, the push notification is sent to the device where Authenticator was last used.
- If the old phone still has a working Authenticator app, open it and check whether it is showing the approval prompt there instead of on the new phone.
- If so, approve from the old phone once so the registration/transfer completes for the new phone.
- Remove the old device from the account
- Sign in to the account’s security settings in a browser and remove the old phone as an authentication method so notifications stop going there.
- The FAQ describes this as “Remove old devices” under the section about notifications going to the wrong device.
- Use an alternate verification method if locked out
- If the old phone will not cooperate or is unusable, choose a different verification method during sign-in (for example SMS, if that is configured on the account) to complete sign-in and then reconfigure Authenticator on the new phone.
- Make sure the new phone’s Authenticator is healthy
- Ensure the new phone has the latest Microsoft Authenticator version installed and that notifications and network connectivity are working, as described in the troubleshooting article (update the app, disable battery optimization for Authenticator, verify notification settings, and confirm date/time and OS updates).
If none of the above works and there is no other verification method configured, tenant or account admins typically must reset MFA methods so they can be set up again on the new phone.
References: