I am locked out of MFA and cannot sign in to the Azure portal / switch into
the directories where I am the administrator.
Background:
- I switched phones and could not recover Microsoft Authenticator (cloud restore lists the work account but cannot generate codes / asks me to "sign in to the account").
- On the sign-in page, "Sign in another way" offers SMS and phone call, but selecting EITHER one fails immediately with error 399287 (it does not send a code or place a call — it errors instantly).
- Authenticator push and verification code are unavailable because the device is gone.
- This leaves me with no usable authentication method.
What I have confirmed via the Entra self-service diagnostics:
- The failures are MFA-related, NOT a Conditional Access block (CA = not applied).
- My account has registered methods (a primary mobile ending 81, an alternate mobile ending 18, Authenticator, email, Windows Hello).
- Tenant authentication-methods policy: SMS enabled, voice disabled.
- Error 399287 appears to be a telephony "bad reputation" block on my phone number, which is why both SMS and voice fail at the service level.
Why I cannot self-remediate:
- I am the sole administrator in the affected directories, so there is no other admin who can reset my MFA or require re-registration.
Error evidence (UTC):
- 399287 (SMS/voice, telephony method blocked)
- 50074 Strong authentication required
- 500121 MFA challenge not completed
- 50072 Prompted to enroll / re-register MFA
Request:
Could engineering please (a) remove the phone "bad reputation" block (399287)
on my registered number, and/or (b) reset / require re-registration of my MFA,
or (c) issue a Temporary Access Pass, so I can sign in once and register a
fresh Authenticator and phone on my current device?
I can verify account/tenant ownership privately (callback, email, and DNS on
the verified domains). I'm happy to share the tenant IDs, account UPN, and any
further diagnostics by private message.