A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Follow these steps based on the type of account and access still available.
- Check for any alternative sign-in method
- If this is a work or school account and there is an IT/admin team, request that an admin reset the multifactor authentication (MFA) settings for the account in Microsoft Entra so that a fresh registration with Microsoft Authenticator can be done on the new phone. This is the standard way to break the “endless MFA loop” where Authenticator is required but cannot be accessed.
- If there is another admin in the tenant, that admin should reset the affected user’s MFA (require re-register MFA) so that the next sign-in prompts for new Authenticator setup.
- If this is a work or school account and there is no other admin
- If the account is the only global admin and cannot sign in because Authenticator is unavailable, Microsoft’s Data Protection team must be involved.
- Call Microsoft’s global customer service phone number (see “Customer service phone numbers - Microsoft Support” in the referenced answers) and clearly state:
- Using Office 365/Microsoft 365 for business.
- This is a company account.
- This is the only administrator account.
- Access to Microsoft Authenticator was lost due to a broken/replaced phone.
- Ask the frontline agent to open a service request and escalate to the Data Protection team to reset the admin’s MFA methods.
- Be prepared to verify identity and tenant ownership as requested by the engineer.
- If support is hard to reach (business account)
- As a workaround, create a new trial Microsoft 365 tenant (separate from the locked one) and use its admin center to open a support ticket.
- In that ticket, clearly state that the issue is with a different, existing tenant where the admin is locked out due to Authenticator and needs MFA reset by the Data Protection team.
- If this is a personal Microsoft account
- If any alternative method (SMS, email, etc.) is still configured and accessible, use that method when prompted with “I don’t have access to my Microsoft Authenticator app” and follow the on-screen recovery flow.
- If the recovery flow is blocked or misrouted (for example, asking for phone digits when expecting email), one proven workaround from similar cases is to temporarily disable 2FA from the account security page while still signed in on a trusted device (such as a Windows PC where the session is active). After disabling 2FA, sign in again, then reconfigure MFA and Authenticator on the new phone.
- Keep Authenticator and MFA resilient going forward
- Always configure at least one backup MFA method (SMS, phone call, or email where allowed) so that access is not lost when a device breaks.
- When changing phones, add the new phone to MFA and confirm it works before removing the old device.
If none of the above options are available (no alternative method, no other admin, no active session anywhere), recovery requires working directly with Microsoft support/Data Protection as described; forum moderators and self-service flows cannot override MFA in that situation.
References:
- Microsoft Authenticator FAQs
- Use a screen reader to set up and troubleshoot multifactor authentication
- Cannot authenticate with E-mail when logging into Microsoft Authenticator(iOS). - Microsoft Q&A
- How Do I Regain Access to My Account After Losing Access to Microsoft Authenticator? (Urgent Request). - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A