A cloud-based identity and access management service for securing user authentication and resource access
Error 500121 with a personal Microsoft account used in Azure usually indicates a problem with the Azure MFA profile for that account. In this scenario, the Authenticator app is showing 8‑digit codes while Azure is prompting for a 6‑digit code and push notifications are not arriving, so the MFA configuration is effectively stuck and blocks sign‑in.
For a personal Microsoft account used in an Azure tenant, MFA cannot be reset self‑service from the personal account side; it must be reset from within the Azure tenant where the account is registered.
Use the following approach:
- Have an administrator in the tenant reset MFA for the affected account
If the personal Outlook account is a user or guest in an Azure AD/Microsoft Entra tenant that has other Global Administrators:- A Global Administrator signs in to the Microsoft Entra admin center.
- Go to Identity → Users → All users.
- Select the affected personal Outlook account.
- Open Authentication methods.
- Select Require re‑register multifactor authentication.
- Sign‑in with the affected account again; it should now prompt to set up MFA from scratch and allow registering a working method (new Authenticator registration, SMS, etc.).
- If there is no other Global Administrator (only one admin and it is locked out)
If the personal Outlook account is the only Global Administrator in the tenant and no one else can perform the reset:- Microsoft’s Data Protection / Tenant Recovery process must be involved to verify identity and regain access to the administrator account.
- This requires contacting Microsoft support by phone (customer service phone numbers) or via a separate tenant:
- Optionally create a new trial Microsoft 365/Azure tenant under a different account.
- Sign in to the Microsoft 365 Admin Center of that new tenant.
- Go to Support → Help & support and open a service request.
- Clearly state that access is lost to a different, existing tenant where the locked‑out personal Outlook account is the only Global Administrator, and request Data Protection / Tenant Recovery assistance to reset MFA for that admin account.
- Provide the locked tenant’s domain, the admin UPN (the personal Outlook address), and details of the MFA issue and error 500121.
- If the personal Outlook account itself is locked or has verification issues
If, in addition to the Azure MFA problem, the underlying Microsoft account has verification issues (codes not arriving, account flagged, etc.), use the Microsoft account security and verification guidance:- Go to the Security basics page for the Microsoft account and update or replace security info as described in the verification‑code troubleshooting article.
- Be aware that if the account has been flagged for unusual activity or locked, verification messages might not go through until that is resolved.
Until an admin in the tenant (or Microsoft via Data Protection/Tenant Recovery) resets the MFA registration for the personal account, the stuck 6‑digit vs 8‑digit code mismatch will continue to block sign‑in and prevent raising a support ticket from within the locked tenant.
References: