A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
To regain access and change the two-step verification method when the Google Authenticator codes are not accepted, use an alternative verification method or account recovery, then update/remove the faulty method.
- If at least one other security method still works
- Sign in to the Microsoft account security dashboard and choose Security → Advanced security options.
- Under Ways to prove who you are, use another method (SMS, email, another authenticator, security key, etc.) to complete sign-in.
- Once signed in, locate the entry that corresponds to the incorrect authenticator setup (for example, the app entry tied to the old phone or wrong configuration) and select Remove.
- Add a new sign-in or verification method using Add a new way to sign in or verify and choose the preferred method (for example, SMS, email, or a correctly configured authenticator app). Follow the prompts to verify and save it.
- If passwordless or strict two-step verification is enabled, ensure at least two valid recovery methods are configured so that losing one method does not lock out of the account.
- If all current security methods fail
- For a work or school account:
- Start sign-in and, at the Verify your identity screen, choose I don't have any of these.
- Follow the instructions to replace security info. When all security info is replaced, there is a 30‑day wait before normal sign-in is allowed. During that period, if any old method becomes available again and is used, the pending change is canceled.
- If the password is also not known and no security method works, use the Microsoft account recovery form as described in the recovery guidance and submit as much accurate information as possible.
- For a work or school account:
- If using a work or school account and still locked out
- Contact the organization’s Help desk or IT administrator and ask them to clear or reset multifactor authentication settings. After they clear the settings, the next sign-in will prompt to register MFA again and a new authenticator configuration can be set up.
- Removing or changing two-step verification
- Two-step verification or passwordless sign-in cannot be turned off or changed without first successfully signing in with at least one working method.
- After signing in and reaching Advanced security options, remove the incorrect authenticator entry and configure the preferred two-step method (for example, SMS or a correctly set up authenticator app). If desired, passwordless can be turned off from the Passwordless account section, then a password can be used again along with other verification methods.
For future protection, ensure multiple methods are configured (for example, authenticator app plus SMS or email) so that losing access to one method does not cause lockout.
References:
- How to go passwordless with your Microsoft account
- Common problems with two-step verification for a work or school account
- Work or school account help
- How Do I Regain Access to My Account After Losing Access to Microsoft Authenticator? (Urgent Request). - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Can't sign in to my email - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A