A cloud-based identity and access management service for securing user authentication and resource access
The mobile Authenticator app is not showing a code because the current MFA method for that account is likely configured as push notification (Approve/Deny) rather than a one-time password (OTP) code, or the registration is no longer valid. This must be fixed by resetting MFA for the user.
Use the following options depending on the tenant situation:
- If there is another Global Administrator in the tenant
- A Global Admin signs in to the Azure portal and opens Microsoft Entra ID.
- Go to Users and select the affected user account.
- Open Authentication methods.
- Select Require re-register multifactor authentication.
- Have the user sign in again; they will be prompted to set up MFA from scratch and can re-add the account in Microsoft Authenticator (and, if desired, enable OTP codes).
- "Require re-register MFA so that you can configure the MFA methods again" in the Manage user authentication options article referenced here: https://learn.microsoft.com/en-us/entra/identity/authentication/howto-mfa-userdevicesettings#manage-user-authentication-options
- If there is no other Global Administrator and this user is the only Global Admin
- Forum moderators and normal admins cannot bypass or reset MFA in this case.
- Contact Microsoft Support and have a ticket raised to the Data Protection / Tenant Recovery team. They have specific tools and procedures to verify identity and reset MFA for a locked-out sole Global Admin.
- Use the regional Customer service phone numbers - Microsoft Support page to find the hotline, then clearly state that this is a tenant lockout, that the caller is the only Global Admin, and that MFA needs to be reset.
- The Data Protection team is engaged when the only Global Admin is locked out due to Authenticator issues.
- Support verifies ownership and then resets MFA registration so the admin can sign in and reconfigure the Authenticator app.
- If the issue is that the app is configured but shows no OTP code at all
- For some enterprise accounts, the Microsoft Authenticator entry may only show Approve/Deny notifications and not a 6-digit OTP. In that case, the sign-in screen must be using the correct method (push notification) rather than expecting an OTP.
- If the portal explicitly asks for a 6-digit code but the app entry has no “One-time password code” line, the MFA registration is misaligned and must be reset using one of the two paths above (another Global Admin or Data Protection team).
Until MFA is reset and re-registered, sign-in will continue to fail if the requested factor (OTP code) does not exist in the app.
References:
- I need to reset my mfa methods - Microsoft Q&A
- Global Admin Locked out - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Microsoft Authenticator app doesn't show 6-digit OTP code - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A