A cloud-based identity and access management service for securing user authentication and resource access
For an Entra ID account where Microsoft Authenticator is not showing any code and all sign-in options still point back to Authenticator, the issue must be resolved by changing or resetting the MFA configuration from outside the affected account.
Because sign-in cannot be completed, self-service options are effectively blocked. The supported path is:
- If this is a work/school (Entra ID) account and there is an admin
- Contact the organization’s Microsoft 365/Entra ID administrator.
- The admin must sign in to the Microsoft Entra admin center with an account that still works.
- Admin steps:
- Go to Identity → Users → All users.
- Select the affected user.
- Open Authentication methods.
- Select Require re-register multifactor authentication.
- After this, the next sign-in for the affected user will prompt for fresh MFA registration (new Authenticator setup or another method), breaking the dependency on the old/non-working Authenticator configuration.
- If this is a guest user in another tenant
- An admin in that tenant must perform the same Require re-register multifactor authentication action on the guest user object in their Entra tenant.
- If the affected user is the only admin
- A separate account with Global Administrator rights must be created (or an existing one used) to sign in and reset MFA for the locked-out account, as above.
- If no other admin account exists and the tenant cannot be accessed at all, the escalation path is to contact Microsoft support by phone and work with the data protection team, as described in the referenced Q&A, so they can help restore access for the tenant admin.
- For personal Microsoft accounts (not Entra ID)
- The Entra admin-center reset path does not apply. In that case, use the account recovery and alternative verification methods described in the Microsoft account support articles (SMS, email, etc.). If none of those are available, support cannot override verification for security reasons.
Once MFA has been reset and sign-in is possible again, re-add Microsoft Authenticator as an authentication method and ensure at least one alternative method (SMS, phone call, or another app) is configured so that future lockouts do not depend on a single device.
References: