A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Because the phone with Microsoft Authenticator was stolen and all sign-ins now require a code, recovery depends on what other security methods or admins are available.
- If this is a work or school (Entra ID / Microsoft 365) account and there is another admin
- Ask a Global Administrator in the tenant to reset MFA for the account:
- Admin signs in to the Azure portal and opens Microsoft Entra ID.
- Go to Users → select the affected user.
- Open Authentication methods.
- Select Require re-register multifactor authentication.
- Next sign-in will prompt to set up new MFA methods (new Authenticator app, phone, etc.) on the new device.
- Ask a Global Administrator in the tenant to reset MFA for the account:
- If this is a work or school account and there is no other Global Admin
- This is a tenant lockout scenario. The documented resolution is to work with Microsoft Support / Data Protection:
- Contact Microsoft support (Global Customer Service phone) and clearly state:
- This is a company / work account.
- MFA is enabled and the only method was Microsoft Authenticator on a stolen phone.
- There is no other global admin in the tenant.
- A Data Protection / Tenant Recovery case is needed to reset MFA registration.
- Support will route the case to the Data Protection team, who will verify ownership and help reset MFA so access can be restored.
- Contact Microsoft support (Global Customer Service phone) and clearly state:
- This is a tenant lockout scenario. The documented resolution is to work with Microsoft Support / Data Protection:
- If this is a personal Microsoft account (Outlook/Hotmail/Live)
- When prompted for a verification code and none of the listed methods are accessible, choose “I don’t have any of these” and follow the prompts to:
- Update backup security info, or
- Complete the account recovery process using the recovery form.
- If codes are not arriving to backup methods that still belong to the user, check:
- Junk folder for mail from @accountprotection.microsoft.com.
- That the phone number/email shown (partially masked) is actually correct.
- When prompted for a verification code and none of the listed methods are accessible, choose “I don’t have any of these” and follow the prompts to:
- If the stolen phone was the only security method everywhere
- For work/school: only an admin MFA reset or a Data Protection / Tenant Recovery case can restore access.
- For personal accounts: only completing the recovery flow after selecting “I don’t have any of these” can restore access.
In all cases, after access is restored on a new device:
- Add multiple MFA methods (Authenticator on new phone, SMS, email, security key) so a single lost device does not lock out the account again.
- If the device was used for work, notify the organization’s help desk so they can clear old MFA settings and take any additional security actions.
References:
- Common problems with two-step verification for a work or school account
- Troubleshoot Microsoft verification code issues
- I need to reset my mfa methods - Microsoft Q&A
- Can't sign in to my email - Microsoft Q&A
- Global Admin Locked out - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A