Managing external identities to enable secure access for partners, customers, and other non-employees
Because the Microsoft Authenticator app is tied to the old phone, the existing MFA methods must be reset before access to the tenant can be restored and MFA can be configured on the new device.
Use the following options based on the admin situation in the tenant:
- If there is another cloud/global admin in the tenant
- Ask that admin to sign in to the cloud service portal as an admin.
- Have them go to the Azure MFA user management page:
https://account.activedirectory.windowsazure.com/usermanagement/multifactorverification.aspx. - They should select the checkbox for the affected admin account.
- Select Manage user settings.
- Select Require selected users to provide contact methods again, then select Save.
- After this reset, sign in again; the account will be prompted to set up MFA methods from scratch on the new phone (for example, by adding the Microsoft Authenticator app or a phone number).
- If there is no other admin and this is a tenant lockout
- This is a tenant lockout scenario where no other global admin can reset MFA. In such cases, Microsoft support must involve the Data Protection team to restore access.
- Open a support case with Microsoft (for example, via a phone call to Global Customer Service or via a support ticket from another tenant, as described in the referenced Q&A). Clearly state that:
- Access to the only global admin account is blocked by MFA on a lost/reset phone.
- A reset of the MFA/authentication methods for the tenant admin is required.
- The Data Protection team will contact by email or phone and work with the tenant owner to verify identity and reset the MFA configuration so that sign-in can succeed and MFA can be re-registered on the new device.
- After MFA is reset
- Once access is restored and sign-in succeeds without the old MFA, immediately:
- Reconfigure MFA methods (Microsoft Authenticator, phone, etc.) on the new phone.
- Optionally add backup methods (such as an alternate phone) to avoid lockout if the primary device is lost again.
- Once access is restored and sign-in succeeds without the old MFA, immediately:
References:
- Can't use Azure Multi-Factor Authentication to sign in to cloud services after you lose your phone or the phone number changes
- Use a screen reader to set up and troubleshoot multifactor authentication
- Azure AD B2C: Frequently asked questions (FAQ)
- I need to reset my mfa methods - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- Azure has blocked myphone number for SMS verification due to a “bad reputation” flag - Microsoft Q&A
- Microsoft Authenticator not working - Microsoft Q&A