A cloud-based identity and access management service for securing user authentication and resource access
For this scenario, self-service options are effectively exhausted and intervention from Microsoft support is required. The behavior (personal/Microsoft account “Live ID” used as a guest/admin in a tenant, 8‑digit app code vs. 6‑digit prompt, and no usable phone method) matches cases where the Azure MFA profile is stuck or misaligned between a personal account and a work/tenant context.
Supported paths based on similar resolved cases:
- If the Live ID is a guest/admin in a tenant
- Sign in to the tenant with another account that has Global Administrator rights (or create one if possible in that tenant).
- In the Microsoft Entra admin center, go to:
- Identity → Users → All users
- Select the affected Live ID user
- Open Authentication methods
- Select Require re-register multifactor authentication
- After this, sign in again with the Live ID; it should force a fresh MFA registration and allow configuring a working method (Authenticator, SMS, etc.).
- If there is no other Global Administrator or no tenant access at all
- This becomes a Data Protection / Tenant Recovery case.
- Contact Microsoft frontline support using the regional Customer service phone numbers and request a ticket with the Data Protection team for MFA reset / tenant recovery.
- Clearly state:
- The account is a personal Microsoft account (Live ID) with Visual Studio–based Azure subscriptions.
- MFA cannot be completed because the Authenticator app shows 8‑digit codes while Azure prompts for 6‑digit codes, and the registered phone number is obsolete.
- There is no other admin who can reset MFA.
- Data Protection follows a verification process (ownership proof, tenant details) and can reset MFA registration from their side, as described in similar cases.
- If the account is locked or throttled due to repeated attempts
- If repeated failed sign-ins have occurred, wait and avoid further attempts for a period, then retry once support has adjusted MFA or after a reset is triggered.
- If all security info is lost on a Microsoft account
- For a pure Microsoft account (not work/school), if all security info is inaccessible, use the account recovery form path:
- Review Help with the Microsoft account recovery form.
- Submit via Recover account.
- This is only applicable if the problem is purely on the Microsoft account side and not the tenant MFA profile.
- For a pure Microsoft account (not work/school), if all security info is inaccessible, use the account recovery form path:
Given the description (Live ID tied to Azure subscriptions, mismatched MFA behavior, and no working methods), the practical resolution is to:
- Use another Global Admin to run Require re-register MFA on the affected user if possible; otherwise
- Open a support case via phone and have it escalated to the Data Protection team for MFA reset / tenant recovery.
References:
- Reset Personal Azure MFA - Microsoft Q&A
- Global Admin Locked out - Microsoft Q&A
- Microsoft Authenticator app doesn't show 6-digit OTP code - Microsoft Q&A
- Troubleshoot Microsoft verification code issues
- Common problems with two-step verification for a work or school account
- Can't use Azure Multi-Factor Authentication to sign in to cloud services after you lose your phone or the phone number changes
- I can't sign in to my Microsoft account
- Microsoft account has been locked
- I need to reset my mfa methods - Microsoft Q&A
- "Account verification system is having trouble" error message when you try to sign in by using a work or school account