Unable to access personal Azure Portal due to MFA issue.

WH 25 Reputation points
2026-04-23T07:37:20.09+00:00

Hi all,

Hoping @Anonymous can assist.

I have been dealing with an ongoing Azure account access issue and would appreciate some advice.

I have an Azure account with an active subscription and several resources associated with it. My understanding is that this account is classified as a Personal Microsoft account.

Recently, I have been unable to access the Azure portal. The username and password are accepted successfully, but the final MFA step fails.

The system requests approval through the Microsoft Authenticator app linked to the account, however:

  • No MFA notification is received
  • Entering a verification code is also not accepted

I contacted Microsoft Support for assistance with resetting MFA so that I could reconfigure it.

Instead, they assisted with creating a separate Work or School account, which now gives access to the Microsoft admin portal and allows sign-in to Azure services. However, the original Azure subscription is still linked to the Personal account, so I cannot view or manage the subscription through the new account.

At this point, I am unsure how best to proceed. It seems the possible options are:

  1. Reset MFA on the original Personal account so access can be restored
  2. Transfer the Azure subscription to the Work or School account

My preference would be Option 1, as there is no real need to maintain the Work or School account if the original account can be recovered.

Has anyone experienced something similar, or can anyone advise on the best way to resolve this?

Thanks in advance.

Microsoft Security | Microsoft Entra | Microsoft Entra ID

Answer accepted by question author
Raja Pothuraju 47,820 Reputation points Microsoft Employee Moderator
2026-04-23T09:16:01.8366667+00:00

Hello @WH,

As discussed over call, you were able to log in to your Azure tenant at admin.cloud.microsoft.com. To reset your MFA, we created a new user with Global Administrator rights. Using this new account to log in to the Azure Portal, we successfully reset the MFA for your personal account, which had been added as a guest account in the tenant.

Below are the steps we followed to reset the MFA:

  1. Sign in to the Microsoft Entra admin center.
  2. Navigate to Identity > Users > All users.
  3. Select the affected user, then choose Authentication methods.
  4. At the top of the window, click on "Require re-register MFA".

Screenshot of manage authentication methods from the Microsoft Entra admin center.

After this is done, you should be able to sign in again and register a new MFA authentication method when prompted.

Was this answer helpful?


2 additional answers

Sort by: Most helpful
  1. Daniel Vanoye 0 Reputation points
    2026-09-18T20:53:59.5166667+00:00

    I am locked out of my personal Azure Pay-As-You-Go subscription due to mandatory MFA. My consumer MSA account generates an 8-digit code, but the Azure Portal/Entra ID tenant prompts for a 6-digit code. No push notifications are arriving. I am the sole Global Administrator. Please route this to the Data Protection / Tenant Recovery Team to issue a Temporary Access Pass (TAP) or trigger a tenant-side MFA re-registration.

    Was this answer helpful?

    0 comments No comments

  2. AI answer

    2026-04-23T07:37:39.0033333+00:00

    Based on the described situation and the provided context, the resolution path is:

    1. The original personal Microsoft account is now a guest user in an Azure AD tenant that has MFA enabled.
    2. MFA for that guest account is misconfigured or stuck, so sign-in to the Azure portal with that identity cannot complete.
    3. A new work or school account (cloud-only account in the same tenant) has been created and granted Global Administrator rights so that tenant-level settings, including MFA for other users, can be managed.

    To restore access to the original account (Option 1), follow the same pattern used in the referenced case:

    1. Sign in to the Microsoft Entra admin center using the new work or school account that has Global Administrator rights.
    2. Go to Identity → Users → All users.
    3. Locate and select the affected user object that represents the original personal account (the guest account that owns the subscription).
    4. Open Authentication methods for that user.
    5. At the top of the Authentication methods pane, select Require re-register MFA.
    6. Save/confirm the change.

    After this:

    1. Sign out of all sessions and browsers.
    2. Sign in to the Azure portal using the original personal account.
    3. When prompted for MFA, the account should now be forced to go through MFA re-registration, allowing configuration of a fresh Microsoft Authenticator registration or another MFA method.

    This approach keeps the existing subscription ownership intact and simply resets the broken MFA profile on the guest account, which matches the preferred Option 1.

    If, for any reason, there is no longer any Global Administrator able to perform these steps (for example, if the new work/school admin account is also unavailable), the issue becomes a tenant lockout scenario. In that case, the next step is to open a support case and have it escalated to the Data Protection / Tenant Recovery team so they can verify ownership and reset MFA/restore access, as described in the referenced tenant-lockout cases.

    Transferring the subscription (Option 2) is not covered in the provided context, whereas resetting MFA via a Global Admin is explicitly documented and demonstrated in similar scenarios, so the supported path from the context is to reset MFA on the original account via the new Global Admin account.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.