A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Because the sign-in is locked to Microsoft Authenticator on the old phone, the account must be recovered or MFA reset; this cannot be fixed only from the new app.
Use the option that matches the type of account and what is still accessible:
- If there is another MFA method on the account (phone call, SMS, alternate email)
- On the sign-in screen, choose “I don’t have my Microsoft Authenticator app” or similar.
- When offered other verification methods, select phone or email instead of Authenticator.
- Complete sign-in, then immediately go to the Security info / Additional security verification page and either:
- Remove the old phone/Auth app entry, and
- Add the new phone (SMS/voice) and re-add Microsoft Authenticator on the new device.
- If using Microsoft 365 work/school, the screen-reader guide shows the flow via the Additional security verification page and Add sign-in method steps: go to the page, delete the old phone, then add the new phone and install Authenticator on the new device.
- If still signed in on a computer/browser
- While still signed in, open the Security info / Additional security verification page for the account.
- Delete the old phone/Auth app method.
- Add a new phone number and reconfigure Microsoft Authenticator on the new phone.
- If this is a work/school (Microsoft 365/Entra ID) account and no alternative method works
- Contact the organization’s IT/admin and ask them to reset or require re-register MFA for the user account in Microsoft Entra Admin Center. After reset, sign in again and set up Authenticator on the new phone.
- If this is a work/school account and the locked-out user is the only admin
- A self-service fix is not possible. The tenant’s only global admin must work with the Microsoft Data Protection team via Microsoft Support phone to regain access, as described in the referenced Q&A answers. Support will verify identity and reset the admin’s MFA so the new phone can be enrolled.
- If this is a personal Microsoft account and no backup/alternative method works
- Use the account recovery flow (including “I don’t have any of those” if necessary) and follow the prompts to prove ownership and reset security info. Once access is restored, add multiple methods (phone, email, Authenticator on the new phone) so a single device loss does not lock out the account again.
After access is restored, always:
- Add at least one backup method (SMS/phone or alternate email).
- Ensure the new phone’s Authenticator is fully set up and working before removing any remaining old methods.
References:
- Use a screen reader to set up and troubleshoot multifactor authentication
- Troubleshoot problems with Microsoft Authenticator
- Authentication did not complete
- Cannot authenticate with E-mail when logging into Microsoft Authenticator(iOS). - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- I need to reset my mfa methods - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A