A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
If the Microsoft Authenticator app on a new phone is not working and sign-in is blocked by MFA, the options depend on whether this is a work/school (Microsoft Entra / Microsoft 365 business) account and whether there is another admin.
- Try an alternative MFA method
- On the sign-in screen, when prompted for Authenticator, look for options like “Use a different verification option” or “I can’t use my Microsoft Authenticator app right now”.
- If SMS, phone call, or another method was previously configured, select it and complete sign-in that way.
- If repeated failed attempts have occurred, Microsoft Entra MFA may temporarily block more attempts. In that case, wait and try again later or use a different MFA method if available.
- If this is a work or school account and there is an admin
- Contact the organization’s Microsoft 365 / Entra ID administrator or Help desk and ask them to reset MFA settings.
- Admin steps (summary from guidance):
- Go to Microsoft Entra admin center (https://entra.microsoft.com).
- Navigate to Users → All users → [select the user] → Authentication methods.
- Use Require re-register multifactor authentication so the user can set up MFA again on the new phone at next sign-in.
- If this is a work or school account and the locked-out user is the only admin
- The only-admin scenario requires Microsoft’s Data Protection team to verify identity and reset MFA.
- Call Microsoft’s Customer service phone numbers - Microsoft Support and request a ticket with the Data Protection team to reset the admin’s MFA.
- When navigating the phone system, clearly state:
- The problem is with Authenticator.
- The product is Office 365 for business / company account.
- The caller is the only administrator and is locked out due to MFA.
- If direct phone support is difficult to reach, one documented workaround is:
- Create a new trial Microsoft 365 tenant (separate environment) using a business trial.
- In the new tenant’s Microsoft 365 admin center, open Support → Help & support and submit a ticket explaining that access is needed to a different, existing tenant where the caller is the only admin and is locked out by MFA.
- If the device was changed but the old phone is still available
- If the old phone still has a working Authenticator registration, use it once more to sign in.
- Then go to the Security info / Additional security verification page for the account and:
- Remove the old phone/app registration.
- Add the new phone and reconfigure Microsoft Authenticator following the “Download and install the Microsoft Authenticator app” guidance.
- If no alternative method works and there is no admin access
- For business/work/school accounts, only the organization’s admin or Microsoft’s Data Protection team can reset MFA.
- For personal Microsoft accounts (not covered in the provided context), follow the account recovery and security options on the consumer account portal.
References:
- Use a screen reader to set up and troubleshoot multifactor authentication
- Work or school account help
- Common problems with two-step verification for a work or school account
- Microsoft Authenticator FAQs
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- I need to reset my mfa methods - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Microsoft Authenticator app doesn't show 6-digit OTP code - Microsoft Q&A