re enroll my acount to other devices due to the phone was lost

Moral, Nelvan C 0 Reputation points
2026-05-05T01:00:50.6566667+00:00

Good Day! Requesting to re enroll to Multi-factor Authenticator (MFA) the phone was lost

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-05-05T01:01:04.3166667+00:00

    To re-enroll Multi-Factor Authentication (MFA) on a new phone after the old one was lost, the MFA methods must be reset and then set up again on the new device.

    Follow the path that matches the type of account and permissions.

    1. If this is a work or school account and there is an admin/help desk
    • Contact the organization’s IT help desk or Microsoft 365/Entra ID administrator.
    • Ask them to clear or reset MFA for the account.
      • In Microsoft Entra ID, the admin can:
        1. Sign in to the Azure portal and open Microsoft Entra ID.
        2. Go to Users > select the user.
        3. Open Authentication methods.
        4. Select Require re-register multifactor authentication.
    • After the admin does this, sign in again; the account will be prompted to register MFA on the new phone (Microsoft Authenticator, phone, SMS, etc.).

    If the device was lost or stolen, also inform the help desk so they can update security settings as needed.

    1. If this is a work or school account and there is another cloud/global admin
    • Another admin can reset MFA as above, or use the legacy MFA management page:
      1. Sign in as admin.
      2. Go to https://account.activedirectory.windowsazure.com/usermanagement/multifactorverification.aspx.
      3. Select the affected user.
      4. Choose Manage user settings.
      5. Check Require selected users to provide contact methods again, then Save.
    • The next sign-in for that user will require re-registering MFA on the new phone.
    1. If this is a work or school account and the user is the only global admin
    • If no other admin exists and the admin is locked out because the phone was lost and Authenticator was the only method, Microsoft Data Protection support must assist.
    • Call Microsoft’s global customer service phone number for business and request a ticket with the Data Protection/Tenant Recovery team to reset the admin’s MFA so it can be re-registered on the new device.
    1. If an alternative MFA method exists
    • If another method (SMS, phone call, office phone, etc.) was configured:
      1. At sign-in, when prompted for verification, choose Sign in another way.
      2. Select the alternative method and complete sign-in.
      3. Go to the security info page (for example, https://aka.ms/mysecurityinfo).
      4. Add the new phone/Authenticator app as a sign-in method.
      5. Optionally delete the old Authenticator method associated with the lost phone.
    1. If the mobile device was lost or stolen
    • Do not wait to report it:
      • Inform the organization’s help desk so they can clear MFA settings and make appropriate updates.
      • After settings are cleared, the next sign-in will prompt for MFA registration again on the replacement phone.

    Once MFA is reset and access is restored, set up Microsoft Authenticator on the new phone and consider adding at least one backup method (SMS, phone call, or another device) to avoid lockout in the future.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.