A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Because there is no backup method or recovery code configured, access must be restored by having MFA reset from outside the locked account.
Use the following options, in order:
- If there is another admin in the tenant
Ask another Microsoft Entra / Azure / Microsoft 365 admin to reset MFA for the account:- Sign in to the Azure portal as an admin who still has access.
- Go to Microsoft Entra ID → Users.
- Select the locked-out user account.
- Open Authentication methods.
- Select Require re-register multifactor authentication and save.
- Next time signing in, the account will be prompted to set up MFA again (and can add Microsoft Authenticator on the new device plus at least one backup method such as phone/SMS).
- If there is no other admin and this is not the only global admin
If another global admin exists but is also locked out, that admin can have their MFA reset by a different admin using the same steps above, then they can reset MFA for the rest. - If this account is the only global admin / tenant admin
When there is no other administrator who can sign in and reset MFA, the situation becomes a tenant lockout. In that case, recovery requires Microsoft support (Data Protection / Tenant Recovery) to verify ownership and reset MFA from the backend. The documented pattern from similar cases is:- Open a support case through any remaining channel that does not require the locked account (for example, phone-based Microsoft support for the organization’s subscription, or another tenant/account if available).
- Clearly state that this is a tenant lockout / only global admin locked out due to MFA and request escalation to the Data Protection team.
- After ownership verification, the Data Protection engineer resets MFA for at least one admin account so that sign-in is possible again and additional methods can be added.
- After access is restored
Once back in the account, immediately:- Add at least one additional MFA method (phone/SMS, alternate authenticator, hardware key, etc.).
- If using passwordless or Authenticator, ensure another two-factor method is configured so that passwordless methods can be managed or removed if needed, as described in the guidance for deleting sign-in methods.
There is no self-service way to bypass or disable MFA when the only configured method (Microsoft Authenticator on the old device) is unavailable and no backup methods or codes exist. Recovery must go through another admin or Microsoft support/Data Protection.
References:
- Can't set up MFA because five devices are already registered to use an authenticator app
- Can't use Azure Multi-Factor Authentication to sign in to cloud services after you lose your phone or the phone number changes
- Common problems with two-step verification for a work or school account
- Use a screen reader to set up and troubleshoot multifactor authentication
- How Do I Regain Access to My Account After Losing Access to Microsoft Authenticator? (Urgent Request). - Microsoft Q&A
- Global Admin Locked out - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- Azure has blocked myphone number for SMS verification due to a “bad reputation” flag - Microsoft Q&A