A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
The behavior matches a stuck or mismatched Azure MFA configuration for the account being used in Azure (often a guest/work profile) versus what is configured in Microsoft Authenticator.
Key points from similar resolved cases:
- Azure is explicitly asking for a 6‑digit OTP or push.
- Microsoft Authenticator is showing an 8‑digit code for that entry.
- Push notifications are not arriving.
- This typically indicates the Azure MFA profile for that identity is misconfigured or stuck, especially when the same email is also a guest or former work account.
From the referenced resolutions, there are two main recovery paths, depending on whether there is another admin in the tenant where this Azure identity lives.
- If the account is a guest in an Azure AD/Microsoft Entra tenant that has another Global Administrator
- Sign in to the Microsoft Entra admin center with a different Global Administrator account in that tenant.
- Go to: Identity → Users → All users.
- Locate and select the affected user (the personal account that is added as a guest).
- Open Authentication methods.
- At the top, select Require re‑register multifactor authentication.
- After this, sign in again with the affected account; Azure will prompt to set up MFA from scratch, and a new (correct) method can be registered in Microsoft Authenticator.
This is the same pattern used to fix a personal account that was a guest in a tenant and had a stuck MFA profile.
- If there is no other Global Administrator / tenant lockout scenario
- When there is no other Global Administrator who can reset MFA, the issue is treated as a tenant lockout.
- In such cases, Microsoft Support escalates to the Data Protection / Tenant Recovery team to verify identity and reset MFA from their side.
- The documented approach is to open a support ticket (or have a moderator/support engineer do so) and have the Data Protection team contact the account owner to restore access and clear the MFA registration.
- Additional checks related to Authenticator itself
- Ensure that the account entry in Microsoft Authenticator is the correct one that Azure is prompting for (especially if there are multiple entries with similar names or if there is both a personal and an organizational/guest entry).
- If push notifications are not received at all for any Microsoft account, verify notification settings and network connectivity as described in the troubleshooting guidance:
- Confirm the phone is not in Do Not Disturb/Quiet mode.
- Confirm other apps can receive notifications.
- If some accounts work and others do not, remove the problematic account from Authenticator and add it again, allowing notifications.
However, in the scenario described (8‑digit code shown while Azure expects 6 digits and no push), the effective fix comes from resetting the MFA registration for the identity in the tenant (Require re‑register MFA) or, if that is not possible, working with Microsoft Support/Data Protection to reset MFA at the service side.
References:
- Reset Personal Azure MFA - Microsoft Q&A
- Microsoft Authenticator app doesn't show 6-digit OTP code - Microsoft Q&A
- Global Admin Locked out - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- Troubleshoot problems with Microsoft Authenticator
- Microsoft Authenticator FAQs