A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Your organization’s IT administrator must reset your registered MFA methods because you have no alternative verification method, after which you can register Authenticator on the new phone.
Ask IT to reset MFA
Contact your organization’s IT help desk or Microsoft 365/Entra administrator and request:
“Please require MFA re-registration for my account because I no longer have my old phone and have no other authentication method registered.”
An administrator with at least the Authentication Administrator role should:
- Sign in to the Microsoft Entra admin center.
- Go to Entra ID → Users.
- Select your user account.
- Select Authentication methods.
- Select Require re-register MFA and confirm.
This operation removes the registered Microsoft Authenticator apps and other listed MFA methods, then requires you to configure a new method at your next sign-in.^1^
This is different from resetting your password: a password reset alone does not replace the Authenticator registration.
Register the new phone
After IT completes the reset:
- Start signing in to your work or school account again.
- When prompted to configure security information, choose Microsoft Authenticator.
- On the new phone, open Authenticator.
- Select + → Add account → Work or school account → Scan a QR code.
- Scan the QR code displayed by the registration page.
- Complete the test approval to verify the new registration.
If the automatic registration prompt does not appear, sign in to the Security info page, select Add sign-in method → Microsoft Authenticator → Add, and then scan the displayed QR code.^2^
Do not remove the new Authenticator entry until the test notification succeeds. After access is restored, add another authentication method if your organization permits it.
Important limitations
- Reinstalling Authenticator does not restore usable authentication for this organizational account by itself. For work or school accounts, an Authenticator backup restores only the account name; sign-in and verification are still required.^3^
- Because the account belongs to an organization, its tenant administrator—not a forum moderator or personal Microsoft-account recovery process—controls these authentication methods.
- If this is the organization’s only administrator account and no other administrator can perform the reset, contact Microsoft Support for tenant-access recovery.^4^
References
- Manage user authentication methods for Microsoft Entra multifactor authentication
- How to add your accounts to Microsoft Authenticator
- [iOS](https://support.microsoft.com/authenticator/restore-account-credentials-from-microsoft-authenticator#i-see-sign-in-to-restore-your-account-after-restoring-authenticator-accounts)
- Unable to log into Authenticator app - Microsoft Q&A