A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
The Azure sign-in is still using the old MFA configuration, which is why the codes from the new Microsoft Authenticator setup do not match what Azure expects.
Because the account is protected by Microsoft Entra multifactor authentication, the MFA configuration must be reset by an administrator in the tenant or by Microsoft support. Reinstalling the app or changing settings on the personal Microsoft account (account.microsoft.com) does not change the Azure/Entra MFA profile.
Use one of these paths:
- If there is another Global Administrator in the tenant
- Ask a Global Administrator to sign in to the Microsoft Entra admin center.
- Go to Identity → Users → All users.
- Select the affected user account.
- Open Authentication methods.
- Select Require re-register MFA.
- Sign in again to Azure with the affected account; it will prompt to register MFA from scratch and allow adding a fresh Microsoft Authenticator profile that matches Azure’s expected code format.
- If this is the only admin account on the tenant
When there is only one admin and that admin is locked out by MFA, the Microsoft Data Protection team must reset the MFA:
- Call Microsoft global customer service using the phone numbers listed under Customer service phone numbers - Microsoft Support.
- In the IVR/agent conversation, clearly state:
- The issue is with Authenticator / MFA.
- The product is Office 365 / Azure for business.
- This is a company account.
- This account is the only administrator and is locked out due to MFA.
- Request to create a service request and be routed to the Data Protection team to reset the admin’s MFA.
- Follow their identity verification steps. Once they reset MFA, sign in again and complete MFA registration with the new Authenticator configuration.
If the phone number used for SMS has been blocked (for example, due to a “bad reputation” flag), this also must be cleared by Microsoft support/Data Protection as part of the same ticket.
After the reset is done and sign-in succeeds, register:
- Microsoft Authenticator on the current device, and
- At least one backup method (such as phone/SMS or another app), so there is an alternative if the device is replaced again.
References:
- Troubleshoot problems with Microsoft Authenticator
- Common problems with two-step verification for a work or school account
- Use a screen reader to set up and troubleshoot multifactor authentication
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Reset Personal Azure MFA - Microsoft Q&A
- I need to reset my mfa methods - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Azure has blocked myphone number for SMS verification due to a “bad reputation” flag - Microsoft Q&A
- Microsoft Curate - Troubleshoot Multi-Factor Authentication (MFA)
- Authenticator Did Not Complete Login