A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
For a Microsoft account where access to Microsoft Authenticator is lost and the sign-in keeps forcing Authenticator, there are only two supported recovery paths, depending on whether any security info is still usable and whether this is a personal or work/school account.
- If this is a personal Microsoft account (Outlook/Hotmail/Xbox/consumer M365)
Because the Authenticator method is blocking sign-in and the account is effectively in a restricted state after a full security info change, the only supported options are:
- Use the built-in security info replacement flow
- Start sign-in to the Microsoft account.
- At the “Verify your identity” prompt, choose I don't have any of these.
- Follow the steps to replace security info.
- When all existing security info is replaced, the account enters a 30‑day restricted period where the message "Your security info change is still pending" or "You can't access this site right now" can appear.
- After the 30 days, the new security info becomes active and can be used to sign in.
If all security info was removed and replaced, nothing can shorten this 30‑day period; it is enforced to protect the account.
- If the password is also not working and no security info is usable
- Use the Microsoft account recovery form as the only supported path:
- Review the guidance at Help with the Microsoft account recovery form.
- Submit the recovery request via the Recover account link.
- Provide as much historical and billing information as possible in the form (old passwords, contacts, subject lines, etc.).
Support agents cannot override this process, send verification codes, or manually change security info for consumer accounts.
Relevant steps from the official guidance:
- If the password is known but all security info is lost:
- Begin sign-in to the Microsoft account.
- At "Verify your identity", select I don't have any of these.
- Follow the instructions to replace security info.
- Wait 30 days for the replacement to take effect.
- If the password is not known and no security info is accessible:
- Read Help with the Microsoft account recovery form.
- Submit the request via the Recover account link.
- If this is a work or school (Entra ID / Microsoft 365 business) account
If this is actually a work/school account protected by two-step verification and Authenticator is lost:
- If some security info is still accessible
- Sign in to the Advanced security options page of the work or school account.
- Select Add a new way to sign in or verify and configure a new method (phone, email, etc.).
- Verify the new method with the code sent.
- Expand the old Authenticator/security info entry and choose Remove.
- Do not remove all methods at once; otherwise, the account can be restricted for 30 days.
- If all security info is lost but the password is known
- Begin sign-in to the work or school account.
- At "Verify your identity", select I don't have any of these.
- Follow the instructions to replace security info.
- After replacement, a 30‑day wait is required before normal sign-in is possible.
- If locked out as the only admin on a business tenant
- When there is only one global admin and that admin is locked out by MFA, the documented path is to involve the Microsoft Data Protection team via a support ticket raised through:
- The global customer service phone numbers for Microsoft Support, or
- A separate temporary tenant (trial subscription) used only to open a support case.
- On the phone IVR, clearly indicate:
- The issue is with Authenticator.
- The product is Office 365 for business.
- It is a company account.
- The caller is an administrator and there are no other administrators.
- A service request is needed and must be routed to the Data Protection team to reset MFA for the tenant admin.
This Data Protection route is only available for commercial/tenant admin scenarios, not for consumer Microsoft accounts.
Given the description (Microsoft 365 Family subscription, personal email addresses), this matches a consumer Microsoft account scenario. In that case, only the built-in security info replacement flow and the Microsoft account recovery form are supported. After all security info is replaced, the 30‑day restriction must complete before the new methods can be used; support cannot bypass or shorten this period.
References:
- Troubleshoot Microsoft verification code issues
- Common problems with two-step verification for a work or school account
- What does “Security info change is still pending” mean?
- How Do I Regain Access to My Account After Losing Access to Microsoft Authenticator? (Urgent Request). - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A