Unable to access Azure AD B2C tenant after phone reset – MFA configured on old device

2026-05-12T06:50:05.2533333+00:00

Hello Team,

I am unable to access my Azure AD B2C tenant because Multi-Factor Authentication (MFA) is still linked to my old mobile device.

Recently, I reset/replaced my phone, and the Microsoft Authenticator app configuration was lost. Now, whenever I switch to my Azure AD B2C tenant, it prompts for MFA approval from the old device, which I no longer have access to.

Issue details:

Azure AD B2C tenant access blocked due to MFA

Old phone/authenticator is unavailable

Unable to register MFA on new device because sign-in itself requires MFA

Need assistance to reset/re-register MFA for my account or provide an alternate recovery method

Please help me regain access to the B2C tenant and configure MFA on my new phone.

Thank you.

Microsoft Security | Microsoft Entra | Microsoft Entra External ID

1 answer

Sort by: Newest
  1. AI answer

    2026-05-12T06:50:31.3833333+00:00

    Because the Microsoft Authenticator app is tied to the old phone, the existing MFA methods must be reset before access to the tenant can be restored and MFA can be configured on the new device.

    Use the following options based on the admin situation in the tenant:

    1. If there is another cloud/global admin in the tenant
      1. Ask that admin to sign in to the cloud service portal as an admin.
      2. Have them go to the Azure MFA user management page: https://account.activedirectory.windowsazure.com/usermanagement/multifactorverification.aspx.
      3. They should select the checkbox for the affected admin account.
      4. Select Manage user settings.
      5. Select Require selected users to provide contact methods again, then select Save.
      6. After this reset, sign in again; the account will be prompted to set up MFA methods from scratch on the new phone (for example, by adding the Microsoft Authenticator app or a phone number).
    2. If there is no other admin and this is a tenant lockout
      • This is a tenant lockout scenario where no other global admin can reset MFA. In such cases, Microsoft support must involve the Data Protection team to restore access.
      • Open a support case with Microsoft (for example, via a phone call to Global Customer Service or via a support ticket from another tenant, as described in the referenced Q&A). Clearly state that:
        • Access to the only global admin account is blocked by MFA on a lost/reset phone.
        • A reset of the MFA/authentication methods for the tenant admin is required.
      • The Data Protection team will contact by email or phone and work with the tenant owner to verify identity and reset the MFA configuration so that sign-in can succeed and MFA can be re-registered on the new device.
    3. After MFA is reset
      • Once access is restored and sign-in succeeds without the old MFA, immediately:
        • Reconfigure MFA methods (Microsoft Authenticator, phone, etc.) on the new phone.
        • Optionally add backup methods (such as an alternate phone) to avoid lockout if the primary device is lost again.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.