RESOURCES · SECURITY & EMAIL

Locked out of
Microsoft 365 MFA?

New phone, a lost or reset authenticator app, or the codes just aren't coming through — and now you can't sign in. Here's how to get back in safely, and what only your IT admin can do.

Applies to: Microsoft 365 · Entra ID Time: ~10 minutes Level: Anyone
Quick answer

On the verification screen, click "I can't use my Microsoft Authenticator app right now" or "Use a different method" — you may have a text, call or backup email registered. Got a new phone? Reinstall Microsoft Authenticator and restore from cloud backup. No method works at all? Your IT administrator is the only one who can reset your MFA.

THE FIX

Work through these in order.

  1. Try another verification methodOn the sign-in prompt, choose "Use a different method" / "I can't use my app right now". If you registered a phone number, take the text or call instead — that's the fastest way back in.
  2. Restore Authenticator on your new phoneIf you moved phones and had cloud backup switched on, reinstall Microsoft Authenticator and sign in with the personal account you used for backup (Apple ID / iCloud on iPhone, or your Microsoft/Google account) to restore your accounts.
  3. Use your old device one last timeIf you still have the old phone, approve one more sign-in with it, then go to mysignins.microsoft.com/security-info and add your new device before you retire the old one.
  4. Add a backup method nowWhile you're in Security info, register a second method (e.g. a phone number as well as the app). Two methods means a new phone never locks you out again.
  5. No method at all? Contact your IT adminIf nothing works, your organisation's IT administrator or help desk can reset your MFA so you can re-register. Only they can do this — Microsoft won't reset a work account for an individual.
Security note — this cuts both ways. "I've lost my MFA, please reset it" is one of the most common tricks attackers use to hijack an account. Expect your IT team to verify who you are before resetting — that's them protecting you, not being difficult. And never approve an MFA prompt you didn't personally trigger: if approval requests appear out of nowhere, someone has your password. Deny them, change your password, and tell IT immediately.
STRONGER, SMOOTHER SECURITY

Good security shouldn't lock out your own team.

MFA is essential — but set up poorly it causes lockouts, and set up carelessly it leaves gaps attackers walk through. Our free IT Health Check reviews how your sign-in security, MFA and account recovery are configured, and shows you how to make them both safer and less painful.

KEEP READING

Related resources