A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
To sign back in to Microsoft Authenticator when it is asking for a verification code from the same app, another verification method must be used or the MFA settings must be reset by an administrator or support.
Use these options, in order:
- Try another registered method (if available)
If the account has other methods configured (SMS, email, security key, or another authenticator app), use that method to sign in to the account in a browser first. Once signed in, update the security settings to remove and re-add Microsoft Authenticator on the new device. For personal Microsoft accounts, alternative methods are described in the passwordless and two-step verification guidance. - If this is a work or school (Entra ID / Microsoft 365) account and there is an admin
Ask the organization’s Microsoft 365/Entra administrator to reset the MFA registration:- Admin goes to Microsoft Entra admin center → Users → All users → select the user → Authentication methods → Require re-register multifactor authentication.
After this reset, sign in again and set up Authenticator from scratch by scanning the QR code.
- Admin goes to Microsoft Entra admin center → Users → All users → select the user → Authentication methods → Require re-register multifactor authentication.
- If this is a work or school account and there is no other admin
If the locked-out user is the only administrator, Microsoft’s Data Protection team must be involved to regain access. The recommended path is to contact Microsoft Support by phone (see “Customer service phone numbers - Microsoft Support” in the referenced answer) and have a service request opened specifically for being locked out due to Authenticator/MFA. Support will verify identity and help restore access. - If this is a personal Microsoft account and Authenticator access is lost
For personal accounts, use any other configured authentication method (SMS, email, etc.) to sign in to the Microsoft account security page and then remove the old Authenticator registration:- Sign in to the Microsoft account dashboard → Security → Advanced security options.
- Under Ways to prove who you are, find the entry that sends sign-in notifications to the old device and select Remove.
After that, open Authenticator on the phone and add the account again using the new QR code or sign-in flow.
If no alternative method is available and no admin/support path is possible, the account cannot be added to Authenticator because the app itself is the only proof of identity; in that case, the account recovery process through Microsoft support (for work/school) or the web recovery options (for personal accounts) is required before Authenticator can be used again.
References:
- Authentication methods in Microsoft Entra ID - Microsoft Authenticator app
- How to go passwordless with your Microsoft account
- Common problems with two-step verification for a work or school account
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A