A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Resolve this by either removing the Authenticator registration from the account or having the MFA settings reset, then adding a working sign-in method again.
- Remove the old Authenticator method (if you can still sign in another way)
- Sign in to the Microsoft account dashboard and go to Security > Advanced security options.
- Under Ways to prove who you are, find the entry that corresponds to Send sign-in notification and your device.
- Expand it and select Remove to delete the old Authenticator registration.
- Add a new method (for example, a different phone number, email, or a fresh Microsoft Authenticator registration) so there is at least one working verification option.
- If this is a work or school (Microsoft Entra ID) account and no other method works
- An admin must reset the MFA registration:
- In the Microsoft Entra admin center, go to Users > All users > select the user.
- Open Authentication methods.
- Select Require re-register multifactor authentication.
- After this, the next sign-in will prompt to set up Microsoft Authenticator again from scratch.
- If there is no admin or no alternative method
- For business/education tenants where the affected user is the only admin, Microsoft’s Data Protection team must reset MFA after verifying identity. This is initiated by calling the regional Microsoft support number and asking support to open a ticket to the Data Protection team to reset MFA for the account.
- If this is a personal Microsoft account and Authenticator access is lost
- Use another configured method (backup email, phone, etc.) to sign in and remove the old Authenticator device from Security > Advanced security options.
- If none of the recovery methods are accessible, follow the Microsoft account sign-in helper to regain access to the backup account, then reconfigure Authenticator. If the backup account cannot be accessed, the documented guidance is that support cannot restore Authenticator credentials and the accounts must be re-added once access is recovered.
- After access is restored
- Re-add the account to Microsoft Authenticator:
- Install and open Authenticator.
- Add the work/school or personal account as documented, scanning the QR code or signing in when prompted.
- Optionally, turn on passwordless sign-in so that sign-in can be completed by approving notifications or entering the number shown in the browser.
References:
- Sign in using Microsoft Authenticator
- How to sign out from Authenticator
- Restore account credentials from Microsoft Authenticator
- How to go passwordless with your Microsoft account
- Troubleshoot problems with Microsoft Authenticator
- Authentication methods in Microsoft Entra ID - Microsoft Authenticator app
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- Microsoft Authenticator app doesn't show 6-digit OTP code - Microsoft Q&A