Unable to complete MFA to sign in — SMS and voice both fail with error 399287, Authenticator device lost, sole admin

Uri 40 Reputation points
2026-06-08T15:31:31.8+00:00

I am locked out of MFA and cannot sign in to the Azure portal / switch into

the directories where I am the administrator.

Background:

  • I switched phones and could not recover Microsoft Authenticator (cloud restore lists the work account but cannot generate codes / asks me to "sign in to the account").
  • On the sign-in page, "Sign in another way" offers SMS and phone call, but selecting EITHER one fails immediately with error 399287 (it does not send a code or place a call — it errors instantly).
  • Authenticator push and verification code are unavailable because the device is gone.
  • This leaves me with no usable authentication method.

What I have confirmed via the Entra self-service diagnostics:

  • The failures are MFA-related, NOT a Conditional Access block (CA = not applied).
  • My account has registered methods (a primary mobile ending 81, an alternate mobile ending 18, Authenticator, email, Windows Hello).
  • Tenant authentication-methods policy: SMS enabled, voice disabled.
  • Error 399287 appears to be a telephony "bad reputation" block on my phone number, which is why both SMS and voice fail at the service level.

Why I cannot self-remediate:

  • I am the sole administrator in the affected directories, so there is no other admin who can reset my MFA or require re-registration.

Error evidence (UTC):

  • 399287 (SMS/voice, telephony method blocked)
  • 50074 Strong authentication required
  • 500121 MFA challenge not completed
  • 50072 Prompted to enroll / re-register MFA

Request:

Could engineering please (a) remove the phone "bad reputation" block (399287)

on my registered number, and/or (b) reset / require re-registration of my MFA,

or (c) issue a Temporary Access Pass, so I can sign in once and register a

fresh Authenticator and phone on my current device?

I can verify account/tenant ownership privately (callback, email, and DNS on

the verified domains). I'm happy to share the tenant IDs, account UPN, and any

further diagnostics by private message.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments

Answer accepted by question author
Sridevi Machavarapu 33,820 Reputation points Microsoft External Staff Moderator
2026-06-08T15:32:47.72+00:00

Hello Uri,

Thank you for sharing your details (user's email address, tenant id, phone number, country code and country) with us over Private Message

I have reached out to the engineering team to unblock MFA for your account. They have now unblocked it from the backend and removed the bad reputation on it. You should be able to log in to the Azure Portal without any issues.

Please try logging in and check if you can complete SMS authentication without any errors. Let me know if you encounter any issues.

I hope this information is helpful. Please feel free to reach out if you have any further questions.

If this answers your query, do click 210246-screenshot-2021-12-10-121802.png and Yes for was this answer helpful, which may help members with similar questions. If you have any other questions, let me know in the “comments” and I would be happy to help you.

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

0 additional answers

Sort by: Newest

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.