A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Reinstalling Microsoft Authenticator without having cloud backup enabled removes the local registrations from the app. The MFA registrations themselves remain active on each account, which is why those services still prompt for OTP or approval, but the app no longer has the secrets/configuration needed to generate or approve them. There is no way to “scan them back in” from the app alone; each account’s MFA must be reset or re-registered at the account side.
Use these paths depending on the type of account:
- Work or school accounts (Microsoft Entra / organizational accounts)
- If the organization manages MFA, an admin must reset or re-register MFA for the user.
- From the Microsoft Q&A guidance, admins can require users to re-register MFA so new methods can be configured again. This is done via the user’s authentication options in Microsoft Entra ID.
- If the user cannot sign in at all and is the only admin, the documented path is to contact Microsoft’s Data Protection / support team via the published customer service phone numbers and request an MFA reset for the tenant admin account.
- Personal Microsoft accounts
- For personal accounts, MFA methods (including Authenticator) are managed via the account’s security info page.
- One documented recovery pattern (when still able to sign in another way) is:
- Sign in to the Microsoft account portal.
- Go to Security info.
- Remove the existing Authenticator app entry.
- Add Authenticator app again to re-register the account in the newly installed app.
- This effectively recreates the link between the account and the reinstalled Authenticator.
- Other services/accounts that used Microsoft Authenticator (including personal email accounts)
- For each non-Microsoft service that was using Authenticator for OTP codes, sign-in will now fail because the shared secret is only on the old (now wiped) app.
- The only supported recovery is to use each service’s account recovery or MFA reset process (backup codes, SMS, email recovery, or contacting that service’s support) and then re-add those accounts to Authenticator.
If none of the accounts offer an alternative sign-in method and there is no backup or recovery option configured, recovery requires working with each account’s support or, for work/school accounts, the organization’s IT or Microsoft Data Protection support as described in the referenced Q&A answers.
References:
- I need to reset my mfa methods - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Authenticator locked and cannot access at all after replacing phone - Microsoft Q&A
- Microsoft Authenticator app doesn't show 6-digit OTP code - Microsoft Q&A
- Back up your accounts in Microsoft Authenticator