A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Hi @Luuk Oosterhuis ,
How you recover access depends on which type of account you use to sign in to Azure. Check the sign-in screen: a personal Microsoft account (for example @outlook.com, @hotmail.com, @live.com, or a Gmail address registered as a Microsoft account) follows a different process from a work or school account (Microsoft Entra ID, for example ******@yourcompany.com or ******@yourtenant.onmicrosoft.com).
Option 1: Personal Microsoft account
- Go to the sign-in page, enter your email, and when prompted for the Authenticator approval, select "I can't use my Microsoft Authenticator app right now" or "Sign in another way." If you previously registered another method, such as SMS, an alternate email, or a phone number, use it to verify.
- If you saved a recovery code when you set up two-step verification, you can enter it to regain access and reset your security info.
- If you have no other verification method, fill out the account recovery form at https://account.live.com/acsr. Use a device and network you've signed in from before, and give as much detail as you can (old passwords, subscription details, billing info). Microsoft support agents can't bypass this form, so it is the main recovery path.
- Once you're back in, re-add the Authenticator app and at least one backup method at https://account.live.com/proofs/manage.
Option 2: Work or school account (Microsoft Entra ID)
- If your tenant has another admin: ask a Global Administrator, Authentication Administrator, or Privileged Authentication Administrator to go to Microsoft Entra admin center → Users → [your user] → Authentication methods and either select "Require re-register multifactor authentication" or delete your old Authenticator method. They can also issue you a Temporary Access Pass (TAP), if TAP is enabled, so you can sign in and register the app again.
- If you are the only Global Administrator and are locked out: open a support request from https://azure.microsoft.com/support/create-ticket/ and use the "Can't sign in" option, which works without signing in. Microsoft's Data Protection team will verify that you own the tenant. This usually means adding a DNS TXT record to your verified custom domain, or providing subscription and billing details. After verification, they can reset MFA for your admin account.
- After you regain access, re-register MFA at https://aka.ms/mfasetup (or https://mysignins.microsoft.com/security-info).
If this answer helped, please click "Accept Answer" so others with the same issue can find it.