A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Because the old phone cannot be used to approve sign-ins or show codes, access must be restored by changing or resetting the multifactor authentication (MFA) methods on the account.
Use one of these paths, depending on the type of account and what alternatives are available:
- If this is a work or school (Microsoft Entra ID / Microsoft 365) account and an alternative method exists
- On a PC, start to sign in to the account as usual.
- When prompted for verification, choose Sign in another way (or similar link).
- Select an alternative method that was set up previously (for example, office phone or another verification method) and complete sign-in.
- After signing in, go to the Security info / Additional security verification page and remove the old phone as an authentication method, then add the new phone and install/configure Microsoft Authenticator there.
- If this is a work or school account and no alternative method works
- Contact the organization’s IT help desk or Microsoft 365 administrator and request an MFA reset.
- An admin can go to Microsoft Entra admin center → Users → select the user → Authentication methods → Require re-register multifactor authentication. This forces a fresh MFA setup on the new phone.
- If this is a work or school account and the user is the only global admin
- This is a tenant lockout scenario. The Microsoft Data Protection team must be involved to verify identity and reset MFA.
- Call Microsoft Support using the regional customer service phone number and clearly state that:
- This is an Office 365 for business / company account.
- The caller is the only administrator.
- The administrator is locked out due to Microsoft Authenticator / MFA and cannot approve sign-ins.
- The frontline agent should escalate to the Data Protection team, who will verify identity (using business documentation and contact details) and then reset MFA or add another authentication method so the account can be accessed again.
- If this is a personal Microsoft account
- Use the account recovery and two-step verification management options described under personal-account MFA guidance (for example, turning two-step verification off or changing methods) from a browser, if any backup method (email, SMS, etc.) is still usable.
- If no backup method works, follow the standard account recovery flow for personal Microsoft accounts.
Once access is restored by one of the methods above, configure the new phone:
- Install Microsoft Authenticator on the new device.
- Sign in to the account using the now-working MFA method.
- Add the new phone as an MFA method and remove the old phone so future sign-ins no longer depend on the broken device.
References:
- Use a screen reader to set up and troubleshoot multifactor authentication
- I can't sign in to my Microsoft account
- How Do I Regain Access to My Account After Losing Access to Microsoft Authenticator? (Urgent Request). - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- Microsoft Authenticator not working - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A