A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
- Stop all sign-in, password reset, and verification attempts for at least 24 hours. Repeated failed sign-ins or repeated verification requests can trigger a temporary lock or rate limit, and additional attempts can prolong it.
- Do not sign out of the account on either the old phone or the new phone. Since the account is still signed in on both devices, keep that access intact.
- After the waiting period, try the password reset again from a device and location previously used with that account. Completing recovery from a recognized device and usual location improves the chance of success.
- If the password reset flow asks for a verification code, enter the code sent to the recovery email. If code delivery or validation fails again, use the verification-code troubleshooting guidance.
- If access to security info has been lost:
- If access remains to some security info, sign in to Advanced security options, add a new way to sign in or verify, confirm it with a code, then remove the old verification method.
- Do not change all security info at the same time, because the account may be restricted for 30 days.
- If access to all security info is lost, at the Verify your identity prompt select I don't have any of these and follow the steps to replace the security info. After replacement, there is a 30-day wait before sign-in is allowed.
- If the account is still blocked after the cooldown and normal reset flow does not work, use the Sign-in Helper or the account recovery form.
- If unusual activity triggered the block, signing in from a trusted device or usual location can help. Since the account is still active on the existing phones, those devices are the safest starting point.
After access is restored, add the new phone as a sign-in or verification method before removing any remaining working method.
References: