PROBLEM WITH AUTHENTICATOR APP - CANNOT LOGIN INTO MY MICROSOFT BUSINESS ACCOUNT

Phương Hoàng 0 Reputation points
2026-09-25T09:33:08.2366667+00:00

Dear Microsoft Team,

I need assistance recovering my company's Microsoft 365 Business account. I purchased the license key from CellphoneS in Vietnam and have been using it for nearly three months. I am designated as the account administrator, and the account allows for simultaneous use on up to five devices. Typically, when my colleagues log in, I am the one who approves the request via the Authenticator app. However, the phone containing the Authenticator app is now broken and unusable. Although I transferred my backed-up data to a new phone, attempting to log in via the Authenticator app triggers a verification prompt that I am unable to complete. I would greatly appreciate it if your team could look into this and provide assistance; I look forward to hearing from you as soon as possible. Thank you.

My account: [Moderator note: Personally Identifiable Information removed] @RayVinaCoLtd.onmicrosoft.com

[Moderator note: Personally Identifiable Information removed]

Email: [Moderator note: Personally Identifiable Information removed]  Web [Moderator note: Personally Identifiable Information removed]

-[Moderator note: Personally Identifiable Information removed]

-[Moderator note: Personally Identifiable Information removed]

Microsoft 365 and Office | Subscription, account, billing | For business | Other
0 comments No comments

3 answers

Sort by: Most helpful
  1. Vincent Choy 11,265 Reputation points Volunteer Moderator
    2026-10-08T08:47:16.0566667+00:00

    For anyone else reading this and hoping to avoid the same lockout.

    This usually follows from how the tenant was set up, not from Authenticator itself.

    Microsoft’s normal small-business setup is:

    1. At least two Global Admin accounts, each with its own authenticator. Ideally also one emergency admin account that is cloud-only, unlicensed, on the .onmicrosoft.com domain, and not dependent on the same phone. Admin-only accounts do not need a license. Keep those details somewhere the business can reach if a phone is lost.
    2. One license per person. On a business plan the five-device allowance is that person’s own devices, not one login shared by five people. Sharing the login is outside the product terms, and it also means one lost phone locks every person who was using that account.
    3. Optionally, give your Microsoft reseller delegated admin (GDAP), including rights to reset MFA. That only helps if the relationship is still active.

    In this case one license is being shared, and that same account is the only Global Admin. It costs less, until the authenticator is lost. Then there is no second admin who can reset MFA.

    Recovery is a tenant-lockout case with Microsoft’s Data Protection team, raised by phone or from a temporary trial tenant. It often takes days to a few weeks, and it depends on proving ownership (billing, domain, company details). Informal setups sometimes cannot produce that proof, and then recovery stalls or fails. The data is still there. Nobody can get in to administer it.

    Was this answer helpful?

    0 comments No comments

  2. Julie Huynh 3,770 Reputation points Independent Advisor
    2026-09-25T10:48:23.23+00:00

    Dear @Phương Hoàng,

    Good day! Welcome to Microsoft Q&A forum!

    Thank you for reaching out, and I’m sorry to hear about the difficulty accessing your Microsoft 365 Business account after your phone was damaged.

    Regarding this situation, since you're an admin, please check to see if there are other IT admins in your organization who can help you with the Multi-Factor Authentication (MFA) reset following the step-by-step instructions provided in the referenced article: Manage user authentication options{0B5167E1-25BE-4AB4-8B05-BF5F4B41CBFA}

    Here's how to find your IT Admin: How do I find my Microsoft 365 admin? (please also kindly reach out to your colleagues, managers, etc. to see if they have the IT department contact) 

    {0FAF2C6F-8128-4E43-BF27-03AE8713B319}

    If you're the only admin, in this situation, the Microsoft Data Protection Team has tools and processes in place to verify identity and regain access to administrator accounts.

    Please let me know if you're the only admin of your organization so that I could provide you with suitable steps accordingly.

    Any updates you’re able to share would be really helpful.

    I'm here and happy to help! Thank you for your kindness and patience!


    If the answer is helpful, please click "Yes". If you have extra questions about this answer, please click "Comment". 

    Note: Please follow the steps in [forum documentation] to enable e-mail notifications if you want to receive the related email notification for this thread. 

    Was this answer helpful?


  3. Victor Waweru 6 Reputation points
    2026-09-25T09:56:46.6833333+00:00

    Hi NGUYEN LE HOANG PHUONG,

    Please log in using an administrator account and navigate to Microsoft Entra ID. Locate your user account and perform the following actions:

    1. Revoke all active sessions.
    2. Change the authentication method to either:
      • A phone number, or
        • A Temporary Access Pass (TAP).
        1. Require the user to re-register MFA.

    This process will remove the old authentication registration and allow the new device to be captured and registered during the MFA setup process. Once completed, you should sign in and complete the MFA re-registration on the new device.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.