A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
"Device registration failed" during Microsoft Authenticator setup usually indicates a problem with the account’s authentication configuration or Conditional Access policies, not the browser or the app itself.
Try these steps depending on whether this is a work/school or personal Microsoft account:
- Check for admin restrictions (work or school account)
If this is a work or school account, the error can be caused by Conditional Access or registration policies set by the administrator. In that case, contact the organization’s Microsoft Entra administrator and ask them to:- Confirm that Microsoft Authenticator registration is allowed for the account.
- Check any Security Information Registration Conditional Access policies that might be blocking registration.
- If needed, require re‑registering MFA for the user so the methods can be reset and added again.
"If you receive the message You might be signing in from a location that is restricted by your admin, your admin hasn't enabled this feature for you and probably set up a Security Information Registration Conditional Access policy. You might also receive messages that block registration of Authenticator because your admin has Conditional Access policies set up. In these cases, contact the administrator for your work or school account to use this authentication method."
- Ensure enough authentication methods exist (work or school account)
If the account doesn’t have enough existing authentication methods to get a strong authentication token, adding Authenticator can fail. The app then shows:
In that case, sign in to the account in a browser, go to the Security info / Additional security verification page, and add another method (phone call/SMS) first, then retry adding Authenticator."To set up Microsoft Authenticator, you'll need to go to aka.ms/mfasetup on a web browser."
- Re-add the sign‑in method from Security info (work or school account)
Instead of starting only from the app, add Authenticator from the account’s security page:- Go to the Security info page at
https://mysignins.microsoft.com/security-infoand sign in. - Select Add sign-in method.
- Choose Microsoft Authenticator and select Add.
- Follow the prompts to display a QR code.
- In Authenticator, tap + → Work or school account → Scan a QR code, and complete registration.
- Go to the Security info page at
- If five devices are already registered (work or school account)
If the account already has the maximum number of authenticator app registrations, new device registration can fail. In that case, delete old sign‑in methods:- Go to
https://aka.ms/mysecurityinfo. - Remove some existing Authenticator/phone methods.
- Then retry adding the new device.
- Go to
- Personal Microsoft account (Outlook.com, Hotmail, etc.)
For a personal account, ensure two‑step verification is correctly configured and then add Authenticator as a sign‑in method:- Sign in to the Microsoft account Security page at
https://account.microsoft.com/security. - Select Manage how I sign in → Add a new way to sign in or verify → Use an app.
- Follow the QR code instructions, then enter the code from Authenticator when prompted.
- Sign in to the Microsoft account Security page at
If the error persists after these steps, the next action is to involve the organization’s admin (for work/school accounts) or adjust two‑step verification and sign‑in methods from the Microsoft account Security page (for personal accounts), as device registration failures are typically policy or method‑configuration issues rather than client-side problems.
References: