A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
To re-enroll Multi-Factor Authentication (MFA) on a new phone after the old one was lost, the MFA methods must be reset and then set up again on the new device.
Follow the path that matches the type of account and permissions.
- If this is a work or school account and there is an admin/help desk
- Contact the organization’s IT help desk or Microsoft 365/Entra ID administrator.
- Ask them to clear or reset MFA for the account.
- In Microsoft Entra ID, the admin can:
- Sign in to the Azure portal and open Microsoft Entra ID.
- Go to Users > select the user.
- Open Authentication methods.
- Select Require re-register multifactor authentication.
- In Microsoft Entra ID, the admin can:
- After the admin does this, sign in again; the account will be prompted to register MFA on the new phone (Microsoft Authenticator, phone, SMS, etc.).
If the device was lost or stolen, also inform the help desk so they can update security settings as needed.
- If this is a work or school account and there is another cloud/global admin
- Another admin can reset MFA as above, or use the legacy MFA management page:
- Sign in as admin.
- Go to
https://account.activedirectory.windowsazure.com/usermanagement/multifactorverification.aspx. - Select the affected user.
- Choose Manage user settings.
- Check Require selected users to provide contact methods again, then Save.
- The next sign-in for that user will require re-registering MFA on the new phone.
- If this is a work or school account and the user is the only global admin
- If no other admin exists and the admin is locked out because the phone was lost and Authenticator was the only method, Microsoft Data Protection support must assist.
- Call Microsoft’s global customer service phone number for business and request a ticket with the Data Protection/Tenant Recovery team to reset the admin’s MFA so it can be re-registered on the new device.
- If an alternative MFA method exists
- If another method (SMS, phone call, office phone, etc.) was configured:
- At sign-in, when prompted for verification, choose Sign in another way.
- Select the alternative method and complete sign-in.
- Go to the security info page (for example,
https://aka.ms/mysecurityinfo). - Add the new phone/Authenticator app as a sign-in method.
- Optionally delete the old Authenticator method associated with the lost phone.
- If the mobile device was lost or stolen
- Do not wait to report it:
- Inform the organization’s help desk so they can clear MFA settings and make appropriate updates.
- After settings are cleared, the next sign-in will prompt for MFA registration again on the replacement phone.
Once MFA is reset and access is restored, set up Microsoft Authenticator on the new phone and consider adding at least one backup method (SMS, phone call, or another device) to avoid lockout in the future.
References:
- Can't use Azure Multi-Factor Authentication to sign in to cloud services after you lose your phone or the phone number changes
- Common problems with two-step verification for a work or school account
- Use a screen reader to set up and troubleshoot multifactor authentication
- Can't set up MFA because five devices are already registered to use an authenticator app
- Restore account credentials from Microsoft Authenticator
- I need to reset my mfa methods - Microsoft Q&A
- How Do I Regain Access to My Account After Losing Access to Microsoft Authenticator? (Urgent Request). - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Global Admin Locked out - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- Set up multi-factor authentication for Microsoft 365