A cloud-based identity and access management service for securing user authentication and resource access
Because the phone is lost, the existing Multi-Factor Authentication (MFA) registration must be reset by an administrator so a new device can be enrolled.
- Contact the Microsoft Entra (Azure AD) or Microsoft 365 administrator for the account.
- The admin signs in to the Azure portal and opens Microsoft Entra ID.
- Go to Users > select the affected user.
- Open Authentication methods.
- Select Require re-register multifactor authentication.
- Save the change.
After this, the next sign-in will prompt to set up MFA again (for example, adding Microsoft Authenticator on a new phone or adding a phone number as another method).
If the account is an admin account and there is another global admin in the tenant, that other admin must perform the same “Require re-register multifactor authentication” step.
If the phone was lost or stolen, also inform the organization’s Help desk so they can clear MFA settings and update the account as needed. After settings are cleared, sign-in will again prompt to register MFA on the new device.
References:
- Can't use Azure Multi-Factor Authentication to sign in to cloud services after you lose your phone or the phone number changes
- Can't set up MFA because five devices are already registered to use an authenticator app
- Common problems with two-step verification for a work or school account
- Use a screen reader to set up and troubleshoot multifactor authentication
- I need to reset my mfa methods - Microsoft Q&A
- Global Admin Locked out - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Microsoft Authenticator app doesn't show 6-digit OTP code - Microsoft Q&A