A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Because the old phone had the Microsoft Authenticator app and the new phone doesn’t, the account’s MFA needs to be reconfigured or reset. The exact steps depend on whether this is a work/school (Microsoft Entra / Microsoft 365) account or a personal Microsoft account, and whether there is an admin who can help.
Use the path that matches the situation:
- If there is another MFA method available (SMS, phone call, alternate email)
- On the sign-in screen, choose “I don’t have my Microsoft Authenticator app” (or similar) and select another verification option such as SMS or phone call if it is offered.
- After signing in successfully with that alternate method, go to the security verification / security info page for the account and remove the old phone and app, then add the new phone and re‑set up Microsoft Authenticator.
- For work/school accounts, this is done from the Additional security verification / Security info page as described in the MFA troubleshooting article.
- If this is a work/school account and there is a tenant admin
- Ask the organization’s Microsoft 365 / Entra ID administrator to reset MFA for the account.
- Admin steps (summary from the referenced Q&A answers):
- Go to Microsoft Entra admin center.
- Open Users → All users, select the user.
- Open Authentication methods and choose Require re‑register multifactor authentication so the user can configure MFA again on the new phone.
- If this is a work/school account and the locked-out user is the only admin
- The account recovery must be handled by Microsoft’s Data Protection team.
- Call Microsoft’s customer service phone number for the region (see “Customer service phone numbers - Microsoft Support” in the referenced Q&A) and clearly state:
- Using Office 365 / Microsoft 365 for business.
- This is a company account.
- The caller is the only administrator and is locked out due to Authenticator on a lost/replaced phone.
- A reset of the admin’s MFA / authentication methods is needed.
- If unable to reach the right support team directly, one documented workaround is to:
- Create a new temporary Microsoft 365 trial tenant.
- From that new tenant’s admin center, open a support ticket explaining that access is needed to a different existing tenant where the caller is the only admin and is locked out by MFA.
- Work with Microsoft support / Data Protection to verify identity and reset MFA on the original tenant.
- If this is a personal Microsoft account and no other MFA method works
- Use any still-working sign-in method (for example, still-signed-in browser session on a PC) to access the account’s security settings and remove the old Authenticator method, then add the new phone and re‑set up Microsoft Authenticator.
- If no method works and there is no admin (because it’s a personal account), follow the standard account recovery and verification flow from Microsoft account security pages and, if needed, use the “I don’t have any of those” option to start recovery, understanding that this may remove existing MFA methods so they can be re‑added.
Once access is restored by any of the paths above, install Microsoft Authenticator on the new phone and complete the QR-code setup for each account so that future sign-ins can use the new device.
References:
- Use a screen reader to set up and troubleshoot multifactor authentication
- Authenticator Did Not Complete Login
- Authentication methods in Microsoft Entra ID - Microsoft Authenticator app
- Microsoft Authenticator FAQs
- I need to reset my mfa methods
- Microsoft authenticator sending me into a spiral
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work.
- Requesting a Tenant Admin MFA Reset
- Cannot authenticate with E-mail when logging into Microsoft Authenticator(iOS).