Microsoft Security | Microsoft Entra | Microsoft Entra ID
A cloud-based identity and access management service for securing user authentication and resource access
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
I cannot complete MFA when signing in to the Azure Portal with my
personal Microsoft account. Password authentication succeeds, but the
MFA prompt only offers Microsoft Authenticator (push or 8-digit code),
and both are bound to a phone I no longer own.
What's happening
----------------
- The sign-in URL contains:
claims={"id_token":{"acrs":{"essential":true,"value":"p1"}}}
which indicates a Conditional Access policy on Azure Portal requiring
authentication context "p1" (strong / phishing-resistant MFA).
- "Sign in another way" exposes no alternate methods (no SMS, email,
voice, passkey) — confirming the Entra-side strong-auth registration
only contains the lost Authenticator device.
- I can sign into account.microsoft.com/security and I have multiple
methods registered there (email, SMS, TOTP, passkey, plus the legacy
Authenticator entry dated 23/09/2015 which is the lost device).
However those are consumer-side methods and do not satisfy the
Entra-side p1 requirement for Azure Portal.
- The Entra-side principal UPN is live.com#******@gmail.com
(legacy MSA-in-Entra format).
What I have already tried
-------------------------
1. Added the account to Microsoft Authenticator on a new iPhone via
"Personal Microsoft account" sign-in. 8-digit codes from that entry
are rejected by Azure Portal MFA.
2. Registered a fresh TOTP entry via QR scan from the consumer security
page ("Other account" type). The 6-digit code is rejected by Azure
Portal MFA.
3. Confirmed iPhone time is auto-synced.
4. Tried https://mysignins.microsoft.com/security-info and
https://aka.ms/mfasetup directly — both require the same MFA.
5. Tried https://entra.microsoft.com — same MFA wall.
6. Attempted account recovery via https://account.live.com/acsr but
that form does not apply to two-step verification scenarios.
7. Tried Cloud Shell from the Azure mobile app (which IS logged in) to
use Microsoft Graph for self-service — Graph API access is blocked
for the MSA principal, returning credential errors.
What I need
-----------
Either:
(a) Reset MFA registration on this principal so I can enroll
Microsoft Authenticator on my new iPhone, or
(b) Temporary CA policy exclusion (~1 hour) so I can self-register
a new authenticator, then re-include.
I am ready to provide identity verification details (contact email,
phone, tenant ID, subscription ID, country, timezone, etc.) via
private message to a moderator.
Note: I have already seen the resolved thread "Locked out of my
personal Azure account due to MFA Issues" — my situation is
essentially identical and I'm hoping for the same routing to the
Data Protection team.
A cloud-based identity and access management service for securing user authentication and resource access
Hello @Ian Hickey
As discussed offline you were able to reset MFA by logging into https://admin.cloud.microsoft.com from an inprivate window and with the steps shared offline
If the resolution was helpful, kindly take a moment to click on
and click on Yes for was this answer helpful. And, if you have any further query do let us know.