Microsoft 365 features that help users manage their subscriptions, account settings, and billing information.
Azure uses its own multi-factor authentication profile, separate from the general Microsoft account security settings. Changing the Microsoft account to password-only does not automatically reset Azure MFA, so Azure continues to require a code from the removed authenticator.
For a personal account used in Azure, the MFA profile typically must be reset by an administrator in the tenant where the account is used, or via Microsoft support. From the provided scenarios, the effective resolutions were:
- If the account is a guest in an Azure/Entra tenant
- Sign in to Azure/Entra with another Global Administrator account in that tenant (or have the tenant admin do this).
- Go to Microsoft Entra admin center → Identity → Users → All users.
- Select the affected user (the personal Microsoft account).
- Open Authentication methods.
- Select Require re-register multifactor authentication.
- Next time signing in with the personal account, Azure will prompt to set up MFA again, allowing a new authenticator app or another method to be registered.
- If there is another Global Administrator in the tenant
- That admin can follow the same steps above (Require re-register multifactor authentication) for the locked-out account.
- If the locked-out account is the only Global Administrator
- This cannot be fixed from the portal because no admin can sign in.
- The documented path is to work with Microsoft Support/Data Protection to verify identity and reset MFA for at least one admin account. This is what was done in similar cases:
- Call Microsoft support using the regional customer service phone number and clearly state that the Global Admin is locked out due to lost authenticator and there is no other admin.
- Ask for escalation to the Data Protection/Tenant Recovery team.
- After identity verification, the Data Protection engineer can reset MFA registration or help create a new admin account, which can then reset MFA for the original account.
- If the personal Microsoft account is only a consumer account (no Azure tenant)
- For consumer sign-in issues, use the Microsoft account sign-in helper and recovery tools referenced under “I can't sign in to my Microsoft account”. However, since Azure is already prompting for MFA and the account is tied to an Azure tenant, the practical fix still requires an admin or Microsoft support to reset the Azure MFA profile as in steps 1–3.
Because the Azure sign-in prompt is not offering alternative verification options and self-service MFA reset for personal accounts is not available, the only supported resolution path is:
- Use another Global Admin in the tenant to trigger Require re-register multifactor authentication, or
- If no other admin exists, work with Microsoft support/Data Protection to reset MFA for the tenant’s admin account.
References: