A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
For a personal Microsoft account with two-step verification enabled, the supported path is to replace the security info tied to the lost Authenticator and wait for the security hold to complete.
- Start sign-in to the Microsoft account.
- At the Verify your identity prompt, select I don't have any of these.
- Follow the prompts to replace the security info with methods that are currently accessible.
- After the replacement is submitted, there is a mandatory 30-day wait before sign-in can complete with the new security info.
Important details for this scenario:
- Resetting the password by SMS or secondary email does not remove the existing Authenticator requirement.
- If access to the original Authenticator is lost, support agents are not allowed to send verification codes, reset links, or directly change account details.
- If all current security methods are replaced, the account can be restricted for 30 days as part of the protection process.
- If the old security info becomes available during those 30 days, it can still be used to sign in, and doing so cancels the pending security-info update.
If the issue is specifically with restoring Microsoft Authenticator on the new phone:
- If backup account access is unavailable, support cannot restore Authenticator credentials.
- The account must either be added again after access is recovered, or the Microsoft account sign-in recovery flow must be used first.
If sign-in still fails or loops, use the Microsoft account Sign-in Helper first. If no problem is detected there, continue with the security-info replacement flow above.
References: