Locked out of personal Microsoft account for Azure Portal due to MFA — lost authenticator device, no fallback methods?

Ian Hickey 20 Reputation points Microsoft Employee
2026-05-27T10:57:52.2+00:00
I cannot complete MFA when signing in to the Azure Portal with my
personal Microsoft account. Password authentication succeeds, but the
MFA prompt only offers Microsoft Authenticator (push or 8-digit code),
and both are bound to a phone I no longer own.

What's happening
----------------
- The sign-in URL contains:
    claims={"id_token":{"acrs":{"essential":true,"value":"p1"}}}
  which indicates a Conditional Access policy on Azure Portal requiring
  authentication context "p1" (strong / phishing-resistant MFA).
- "Sign in another way" exposes no alternate methods (no SMS, email,
  voice, passkey) — confirming the Entra-side strong-auth registration
  only contains the lost Authenticator device.
- I can sign into account.microsoft.com/security and I have multiple
  methods registered there (email, SMS, TOTP, passkey, plus the legacy
  Authenticator entry dated 23/09/2015 which is the lost device).
  However those are consumer-side methods and do not satisfy the
  Entra-side p1 requirement for Azure Portal.
- The Entra-side principal UPN is live.com#******@gmail.com
  (legacy MSA-in-Entra format).

What I have already tried
-------------------------
1. Added the account to Microsoft Authenticator on a new iPhone via
   "Personal Microsoft account" sign-in. 8-digit codes from that entry
   are rejected by Azure Portal MFA.
2. Registered a fresh TOTP entry via QR scan from the consumer security
   page ("Other account" type). The 6-digit code is rejected by Azure
   Portal MFA.
3. Confirmed iPhone time is auto-synced.
4. Tried https://mysignins.microsoft.com/security-info and
   https://aka.ms/mfasetup directly — both require the same MFA.
5. Tried https://entra.microsoft.com — same MFA wall.
6. Attempted account recovery via https://account.live.com/acsr but
   that form does not apply to two-step verification scenarios.
7. Tried Cloud Shell from the Azure mobile app (which IS logged in) to
   use Microsoft Graph for self-service — Graph API access is blocked
   for the MSA principal, returning credential errors.

What I need
-----------
Either:
  (a) Reset MFA registration on this principal so I can enroll
      Microsoft Authenticator on my new iPhone, or
  (b) Temporary CA policy exclusion (~1 hour) so I can self-register
      a new authenticator, then re-include.

I am ready to provide identity verification details (contact email,
phone, tenant ID, subscription ID, country, timezone, etc.) via
private message to a moderator.

Note: I have already seen the resolved thread "Locked out of my
personal Azure account due to MFA Issues" — my situation is
essentially identical and I'm hoping for the same routing to the
Data Protection team.
Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments

Answer accepted by question author
Rukmini 43,995 Reputation points Microsoft External Staff Moderator
2026-05-27T11:05:44.1333333+00:00

Hello @Ian Hickey

As discussed offline you were able to reset MFA by logging into https://admin.cloud.microsoft.com from an inprivate window and with the steps shared offline

If the resolution was helpful, kindly take a moment to click on 210246-screenshot-2021-12-10-121802.pngand click on Yes for was this answer helpful. And, if you have any further query do let us know.

Was this answer helpful?

2 people found this answer helpful.
0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.