I have entered a loop with the Authenticator app

Salom Roser 20 Reputation points
2026-08-14T09:18:46.5566667+00:00

I used the authenticator app a while back when I logged in my work account for the first time, and I had deleted the authenticator app after a month of not using it. When I reinstalled it to complete a setting up task, the app itself asked me to use the authenticator app... to enter the authenticator app.

It also doesn't provide any additional ways to log in, no QR code, no SMS, nothing. Just two options, both using the Authenticator app.

So I can't enter the app, and let alone identify myself in other devices to do anything.

Microsoft 365 and Office | Subscription, account, billing | For business | Other
0 comments No comments

Answer accepted by question author
JeseminQH 515 Reputation points Independent Advisor
2026-08-14T09:52:17.9366667+00:00

Hi @Salom Roser

Regarding your issue, this happens because deleting Microsoft Authenticator does not remove the existing authentication registration from your work account. Your organization’s system still expects approval from the original Authenticator installation, but the reinstalled app no longer has the credentials required to provide that approval.

Therefore, please contact your organization’s IT help desk or Microsoft 365 administrator and ask them to complete the following steps:

  1. Sign in to the entra.microsoft.com as at least Authentication Administrator.   
  2. Select User -> All user.   Select the user (your account) to act on and select Authentication methods. then select Require re-register of multi-factor authentication.    
  • Require re-register MFA: This disables all previous authentication methods. You'll then be prompted to configure a new MFA authentication method the next time you try to sign in, so you can set up from the start and add a new authenticator app.   

 User's image

For more details, please refer to: Manage user authentication methods for Microsoft Entra multifactor authentication. 

Find Your Microsoft 365 Admin: If you’re unsure who the Global Admin is within your organization, you can find guidance on locating them here: How do I find my Microsoft 365 admin?

User's image

Note: Once re-registration is triggered, all your existing MFA methods such as phone numbers, Authenticator app, or other verification options will be removed. You will need to set up new MFA methods during your next login. Please ensure you have access to a valid phone number or the Microsoft Authenticator app before attempting to sign in again.   

Hopefully it will help work with your issue and if you have any other questions or need further assistance, feel free to ask.   


If the answer is helpful, please click "Yes". If you have extra questions about this answer, please click "Comment".

Note: Please follow the steps in the forum documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

1 additional answer

Sort by: Newest
  1. AI answer

    2026-08-14T09:19:13.1033333+00:00

    This is a work or school account MFA lockout loop. Deleting the Authenticator app removed the app’s ability to approve sign-in or generate codes, and if no other verification method was configured, there is no self-service way to complete sign-in from the app alone.

    What to do:

    1. Check whether another sign-in method is available.
      • On the sign-in screen, look for Sign in with another method.
      • If SMS, phone call, or another method was previously configured, use that to get in.
    2. If no other method appears, contact the organization’s IT admin or help desk.
      • Ask them to reset MFA settings or require re-registration for multifactor authentication on the account.
      • This is the standard fix for an Authenticator loop on a work or school account.
    3. If the admin can access Microsoft Entra ID, they can do this in:
      • Azure portalMicrosoft Entra IDUsers → select the user → Authentication methodsRequire re-register multifactor authentication.
    4. After the reset, sign in again.
      • The next sign-in should prompt setup of Authenticator again from the beginning.
    5. If an old phone still has Authenticator registered, check it.
      • Push notifications can be sent to the device where Authenticator was last used.
      • If accessible, approve the sign-in there, then remove old devices from the account settings.
    6. If the sign-in page says the broker app did not complete login, finish the sign-in in Authenticator, Company Portal, or the primary Microsoft app on the device.

    Important details:

    • For work or school accounts, whether notifications or alternate methods are allowed is controlled by the organization.
    • If repeated sign-in attempts were made, Microsoft Entra MFA can temporarily block more attempts. In that case, wait and try again later or use a different MFA method if one exists.
    • On Android in China, Authenticator push notifications don’t work; alternate authentication methods are required.

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.