A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
To reclaim access, the Azure sign-in and MFA must be reset by an administrator of the tenant that owns the account where the email is registered.
Because the Outlook address is being used in a third-party company’s Azure tenant, that tenant’s admins control the Microsoft Entra ID (Azure AD) account and its MFA settings. The steps are:
- Contact the third-party company’s IT/admin team
- Explain that the Outlook address is a user/guest account in their Azure tenant and that sign-in is blocked by Microsoft Authenticator MFA that is no longer accessible.
- Ask them to reset MFA for the account in Microsoft Entra ID.
- Admin resets MFA in Microsoft Entra admin center
- An admin in that tenant signs in to the Microsoft Entra admin center.
- Go to Identity → Users → All users.
- Select the affected user (the Outlook email).
- Open Authentication methods.
- Select Require re-register multifactor authentication.
- After this, the next time sign-in is attempted with that account, Azure will prompt to set up MFA again (e.g., new Authenticator app or another method).
- If no other admin exists or the tenant is locked
- If there is no other global admin who can perform the reset, the tenant owner must work with Microsoft Support/Data Protection via a support ticket or phone support to restore access and reset MFA. This can only be initiated by the tenant’s owner/admin, not by the external user.
If the Outlook address is also a personal Microsoft account (for consumer services) and access to its security info is lost, follow the consumer account recovery path:
- If the password is known but some security info is still accessible:
- Sign in to the Advanced security options page.
- Select Add a new way to sign in or verify and configure a new phone/email.
- Confirm via the code sent to the new method.
- Remove old/unavailable security info.
- If the password is known but all security info is lost:
- Start sign-in.
- At Verify your identity, select I don't have any of these.
- Follow the steps to replace security info.
- After replacement, there is a 30-day wait before full sign-in is allowed.
- If the password is not known and no security info is available:
- Review Help with the Microsoft account recovery form.
- Submit the recovery form via Recover account.
These steps recover the personal Microsoft account itself; the Azure tenant MFA for that email still must be reset by the tenant’s admins as described above.
References:
- Reset Personal Azure MFA - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- I need to reset my mfa methods - Microsoft Q&A
- Global Admin Locked out - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- Troubleshoot Microsoft verification code issues