Tag not monitored by Microsoft.
Error code 500121 indicates that Microsoft Entra multifactor authentication (MFA) is blocking sign-in because of repeated or problematic verification attempts. The account is stuck in a loop asking for an Authenticator code/approval, but the app is not presenting a usable prompt or code.
Use these steps, in order, based on what is documented:
- Stop repeated attempts
- Multiple failed MFA attempts can cause Entra MFA to temporarily block further sign-ins as a security measure.
- Wait before trying again and avoid repeatedly submitting new attempts, as this can extend the block.
- Try a different MFA method (if available)
- On the sign-in screen where it asks for the Authenticator code/approval, look for an option such as “Use a different verification option” or similar.
- If another method is configured (SMS, alternate email, hardware key, etc.), select that method and complete sign-in.
- If sign-in succeeds with another method, go to the Security info page for the work/school account and update MFA methods:
- Verify that the phone number or email is correct.
- Add or change methods so there is at least one working alternative to Authenticator.
- If no other MFA method works or is available
- Microsoft Entra MFA may be blocking verification due to unusual activity or high volume of requests.
- In this case, the only supported paths are:
- Wait for the temporary block to clear (this can take time; do not keep retrying in rapid succession).
- Use a different verification method or network if one is available:
- Try switching between Wi‑Fi and cellular data on the mobile device.
- Try signing in from another device or network and see if another method is offered.
- If still locked out and this is a work/school (business) account
- For work or school accounts, only the organization’s IT administrator or Microsoft support can reset MFA settings when the user cannot complete verification.
- If there is an IT admin in the organization:
- Ask the admin to go to the Microsoft Entra admin center, open the user account, and reset/re-register MFA (clear or require re-register of authentication methods). After that, sign-in will prompt to set up Authenticator again.
- If this business account has only one administrator and that admin is locked out (no other admins):
- Microsoft’s Data Protection team must be involved through a support case opened via Microsoft support phone channels, as described in the referenced guidance. They have processes to verify identity and restore access for a locked-out sole admin.
- If still not receiving any codes or prompts
- If SMS or email codes are also not arriving when selected as a method:
- Do not keep making excessive or repetitive requests; this can cause or extend a block.
- Check whether the phone blocks texts from unknown numbers, or whether the email is sending codes to junk/spam.
- If the region has SMS delivery issues or there is heavy compromised traffic from the location, delivery may be delayed and will resolve automatically after some time.
- When access is restored
- Add at least two MFA methods (for example, Authenticator plus SMS or email) so that losing one device or method does not fully block access.
- Consider using passwordless sign-in (Authenticator, Windows Hello, or security keys) for more reliable and secure access.
If none of the above paths work and there is no alternative MFA method and no admin who can reset MFA, the next step is to contact Microsoft support by phone so a ticket can be raised and the Data Protection team can assist with account recovery for the business tenant.
References:
- Common problems with two-step verification for a work or school account
- Troubleshoot Microsoft verification code issues
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A