A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
If the old phone with Microsoft Authenticator no longer works, the fix depends on whether this is a personal Microsoft account or a work/school (Entra ID) account and whether there are other sign-in methods or admins available.
- Try other sign-in methods
- On the Microsoft sign-in page, when asked for a code from Authenticator, choose “I don’t have my Microsoft Authenticator app” or similar.
- Use any other available method (SMS, alternate email, etc.).
- If you can sign in this way, immediately update your security info:
- Go to https://account.microsoft.com → Security → Security info.
- Add a new method (phone, email, or Authenticator app on the new phone).
- Once the new Authenticator is working, remove the old Authenticator entry.
- If this is a personal Microsoft account and Authenticator is locked
- If still able to sign in to the Microsoft account in a browser (for example on a PC), remove and re-add the Authenticator method:
- Sign in at https://account.microsoft.com.
- Go to Security → Security info.
- Remove the existing Authenticator app entry.
- Choose Add sign-in method → Authenticator app and follow the steps to set it up on the new phone.
- This matches the resolution where a user removed the Authenticator app from Security info and then re-added it.
- If still able to sign in to the Microsoft account in a browser (for example on a PC), remove and re-add the Authenticator method:
- If this is a work or school account and there is another global admin
- Ask a global admin in the tenant to reset MFA for the account:
- Admins can use the Require re-register MFA option so the account can configure MFA again on the new phone.
- Ask a global admin in the tenant to reset MFA for the account:
- If this is a work or school account and there is only one global admin (and that admin is locked out)
- This is a tenant lockout scenario. Self-service recovery is not possible.
- The organization’s only option is to work with Microsoft Support/Data Protection:
- Call Microsoft Support using the public Customer service phone numbers - Microsoft Support page.
- Clearly state that this is a lockout of the only global admin due to Microsoft Authenticator on a lost/broken phone.
- The Data Protection team will verify identity and help restore access.
- If still signed in somewhere but cannot complete MFA on the phone
- If still signed in on a Windows PC or browser session, use that session to:
- Temporarily disable or change MFA settings (if allowed for the account type), or
- Add additional sign-in methods (phone, email, new Authenticator app) so that the old phone is no longer required.
- If still signed in on a Windows PC or browser session, use that session to:
If none of the above works and there is no other sign-in method, no other admin, and no active signed-in session, direct assistance from Microsoft Support is required to regain access.
References:
- Troubleshoot problems with Microsoft Authenticator
- Authentication did not complete
- Back up your accounts in Microsoft Authenticator
- Microsoft Authenticator FAQs
- Troubleshoot signing in with a passkey
- Authenticator locked and cannot access at all after replacing phone - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Cannot authenticate with E-mail when logging into Microsoft Authenticator(iOS). - Microsoft Q&A
- I need to reset my mfa methods - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A