Unable to Reset MFA for Personal Azure Account

Siddharth Chandrasekhar 20 Reputation points
2026-05-27T13:53:22.2566667+00:00

Hello,

I have a personal Microsoft Azure account, and after changing my phone, I lost access to the authenticator app that was set up for MFA. Now, whenever I try to sign in, I am prompted to approve the login through the authenticator app or enter a code after entering my password. However, I no longer have access to the authenticator app, and the account does not allow me to set up a new one.

I am not sure how to reset MFA for my personal Azure account so that I can configure the authenticator app again on my new phone. I was able to setup a new MFA method on my Microsoft Account but that seems to not work for Azure logins.

Separately, my personal Microsoft account was also added as an external user in my workplace directory. I was able to contact my workplace IT admin, who reset MFA for that directory, and I successfully set up the authenticator app on my new phone for that work directory.

However, when I go to the Directories page in the Azure portal and click “Switch” in order to switch to my personal default directory, I get stuck in the same loop where it asks me for an authenticator approval or code from the old authenticator app, which I no longer have.

Could you please advise how I can reset MFA for my personal Azure account?

Thank you.

Microsoft Security | Microsoft Entra | Microsoft Entra ID

Answer accepted by question author
Rukmini 43,995 Reputation points Microsoft External Staff Moderator
2026-05-28T13:27:17.52+00:00

Hello @Siddharth Chandrasekhar

As discussed over private messages, you were able to reset MFA by logging into https://admin.cloud.microsoft.com from an inprivate window and with the steps shared offline

If the resolution was helpful, kindly take a moment to click on 210246-screenshot-2021-12-10-121802.pngand click on Yes for was this answer helpful. And, if you have any further query do let us know.

Was this answer helpful?

1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. AI answer

    2026-05-27T13:53:41.0833333+00:00

    For a personal Microsoft account that also exists as a guest in a work Entra ID tenant, the MFA that blocks access to the Azure portal is controlled by the Entra tenant where the sign-in is happening. The working setup in the work directory confirms that the work tenant’s MFA has already been reset correctly; the remaining problem is the MFA configuration tied to the personal/default directory where the account is also present.

    From the provided scenarios in the context, there are two working patterns to reset MFA when locked out:

    1. If there is (or can be) another Global Administrator in the tenant that owns the personal/default directory
      That admin can reset MFA for the affected account so it is forced to re-register MFA on next sign-in:
      1. Sign in to the Microsoft Entra admin center with a Global Administrator account for the tenant that contains the personal/default directory.
      2. Go to Identity → Users → All users.
      3. Select the affected user (the personal Microsoft account object in that tenant).
      4. Open Authentication methods.
      5. Select Require re-register multifactor authentication.
      6. Sign out and sign back in as the affected user; the account will be prompted to register MFA again (e.g., Microsoft Authenticator on the new phone).
      This is the same pattern used in the referenced case where a new Global Administrator account was created, then used to reset MFA for the personal account that had been added as a guest and was stuck in an MFA loop.
    2. If the personal/default directory has only one Global Administrator (the locked-out account)
      In this case there is no other admin who can perform the reset from the portal. The supported path is to work with Microsoft support/Data Protection so they can reset MFA for the tenant admin account:
      • Open a support case with Microsoft and have the request routed to the Data Protection team for an MFA reset / tenant lockout scenario, explaining that:
        • The account is the only Global Administrator for the personal/default directory.
        • MFA is enforced and tied to an old Authenticator instance that is no longer accessible.
      • In similar cases, support has:
        • Verified tenant ownership.
        • Reset MFA for the locked-out admin account or otherwise restored access so that MFA can be re-registered.
      In some documented cases, when no admin could access the tenant, a support ticket to the Data Protection team was created (sometimes via another tenant’s admin center) and that team reset MFA or cleared the lockout.

    Once MFA is reset by either method, sign-in to the Azure portal with the personal account in the personal/default directory will prompt for MFA registration again, allowing configuration of Microsoft Authenticator on the new phone specifically for that directory.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.