unable to login to non federated azure account

2026-05-25T15:08:00.82+00:00

Am unable to login to non federated azure account, its asking the one time code generating in mobile authenticator application , but actually i added the non federated azure account in my mobile authenticator application but not getting any code

Please advise how to fix this , i guess MFA has to reset

Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Oldest
  1. AI answer

    2026-05-25T15:08:15.6766667+00:00

    The mobile Authenticator app is not showing a code because the current MFA method for that account is likely configured as push notification (Approve/Deny) rather than a one-time password (OTP) code, or the registration is no longer valid. This must be fixed by resetting MFA for the user.

    Use the following options depending on the tenant situation:

    1. If there is another Global Administrator in the tenant
      1. A Global Admin signs in to the Azure portal and opens Microsoft Entra ID.
      2. Go to Users and select the affected user account.
      3. Open Authentication methods.
      4. Select Require re-register multifactor authentication.
      5. Have the user sign in again; they will be prompted to set up MFA from scratch and can re-add the account in Microsoft Authenticator (and, if desired, enable OTP codes).
      Guidance for this operation is in:
    2. If there is no other Global Administrator and this user is the only Global Admin
      1. Forum moderators and normal admins cannot bypass or reset MFA in this case.
      2. Contact Microsoft Support and have a ticket raised to the Data Protection / Tenant Recovery team. They have specific tools and procedures to verify identity and reset MFA for a locked-out sole Global Admin.
      3. Use the regional Customer service phone numbers - Microsoft Support page to find the hotline, then clearly state that this is a tenant lockout, that the caller is the only Global Admin, and that MFA needs to be reset.
      This process is described in the Q&A threads where:
      • The Data Protection team is engaged when the only Global Admin is locked out due to Authenticator issues.
      • Support verifies ownership and then resets MFA registration so the admin can sign in and reconfigure the Authenticator app.
    3. If the issue is that the app is configured but shows no OTP code at all
      • For some enterprise accounts, the Microsoft Authenticator entry may only show Approve/Deny notifications and not a 6-digit OTP. In that case, the sign-in screen must be using the correct method (push notification) rather than expecting an OTP.
      • If the portal explicitly asks for a 6-digit code but the app entry has no “One-time password code” line, the MFA registration is misaligned and must be reset using one of the two paths above (another Global Admin or Data Protection team).

    Until MFA is reset and re-registered, sign-in will continue to fail if the requested factor (OTP code) does not exist in the app.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.