Multi Factor Authentication

Gariromo Herbert Chawatama 0 Reputation points
2026-06-30T11:22:33.7166667+00:00

During registration and adding a new account in Microsoft authenticator app.

I scan the QR code and its added.

When i go to enter the generated code i get an error "Device registration failed" have tried different browsers, cleared cache etc. I even tried another authenticator got the same error.

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Oldest
  1. AI answer

    2026-06-30T11:22:52.6166667+00:00

    "Device registration failed" during Microsoft Authenticator setup usually indicates a problem with the account’s authentication configuration or Conditional Access policies, not the browser or the app itself.

    Try these steps depending on whether this is a work/school or personal Microsoft account:

    1. Check for admin restrictions (work or school account)
      If this is a work or school account, the error can be caused by Conditional Access or registration policies set by the administrator. In that case, contact the organization’s Microsoft Entra administrator and ask them to:
      • Confirm that Microsoft Authenticator registration is allowed for the account.
      • Check any Security Information Registration Conditional Access policies that might be blocking registration.
      • If needed, require re‑registering MFA for the user so the methods can be reset and added again.
      The documented behavior for setup errors is:

      "If you receive the message You might be signing in from a location that is restricted by your admin, your admin hasn't enabled this feature for you and probably set up a Security Information Registration Conditional Access policy. You might also receive messages that block registration of Authenticator because your admin has Conditional Access policies set up. In these cases, contact the administrator for your work or school account to use this authentication method."

    2. Ensure enough authentication methods exist (work or school account)
      If the account doesn’t have enough existing authentication methods to get a strong authentication token, adding Authenticator can fail. The app then shows:

      "To set up Microsoft Authenticator, you'll need to go to aka.ms/mfasetup on a web browser."

      In that case, sign in to the account in a browser, go to the Security info / Additional security verification page, and add another method (phone call/SMS) first, then retry adding Authenticator.
    3. Re-add the sign‑in method from Security info (work or school account)
      Instead of starting only from the app, add Authenticator from the account’s security page:
      • Go to the Security info page at https://mysignins.microsoft.com/security-info and sign in.
      • Select Add sign-in method.
      • Choose Microsoft Authenticator and select Add.
      • Follow the prompts to display a QR code.
      • In Authenticator, tap +Work or school accountScan a QR code, and complete registration.
    4. If five devices are already registered (work or school account)
      If the account already has the maximum number of authenticator app registrations, new device registration can fail. In that case, delete old sign‑in methods:
      • Go to https://aka.ms/mysecurityinfo.
      • Remove some existing Authenticator/phone methods.
      • Then retry adding the new device.
    5. Personal Microsoft account (Outlook.com, Hotmail, etc.)
      For a personal account, ensure two‑step verification is correctly configured and then add Authenticator as a sign‑in method:
      • Sign in to the Microsoft account Security page at https://account.microsoft.com/security.
      • Select Manage how I sign inAdd a new way to sign in or verifyUse an app.
      • Follow the QR code instructions, then enter the code from Authenticator when prompted.

    If the error persists after these steps, the next action is to involve the organization’s admin (for work/school accounts) or adjust two‑step verification and sign‑in methods from the Microsoft account Security page (for personal accounts), as device registration failures are typically policy or method‑configuration issues rather than client-side problems.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.