Microsoft authenticator External organization (after phone reset or lost)

Anonymous
2022-07-25T16:17:50.337+00:00

Hello,

I recently lost my phone and now that I have a new one, I need to connect to an external organisation attach to my company microsoft account. The problem is that I have no longer the entry for this external organisation in my authenticator app.

I try to remove the guest account first from https://myaccount.microsoft.com/organizations but I can't remove the guest account because I don't receive any notification on my authenticator app.

I asked the guys from the external organisation to re invite me. I also can't join. I don't receive any notification on my authenticator app.

But the app still seems to work, from https://mysignins.microsoft.com/security-info when I remove the authentication by the application and add it again, I receive the notification correctly.

Anyways I always had this kind of problem with this crap of microsoft-authenticator app and external organization.

Microsoft Security | Microsoft Authenticator

Answer accepted by question author
Carlos Solís Salazar 18,376 Reputation points MVP
2022-07-25T16:30:01.017+00:00

Hi @Anonymous

Thank you for asking this question on the **Microsoft Q&A Platform. **

You will require that the Azure AD External organization "Reset your MFA"

I have provided the steps below to reset and unblock MFA in Azure Active Directory via Azure Portal and PowerShell.

Using Azure Portal:

  • Sign in to the Azure portal with the tenant Global Administrator account.
  • Navigate to Azure Active Directory > Users > All users > Choose the user you wish to perform an action on >** select Authentication methods** > Require Re-register MFA.
  • Once this is done, the next time the user signs in, he/she will be requested to set up a new MFA authentication method.

Note: The user's currently registered authentication methods aren't deleted when an admin requires re-registration for MFA. After a user re-registers for MFA, we recommend they review their security info and delete any previously registered authentication methods that are no longer usable.

Using PowerShell:

  • Install the MSOnline PowerShell module.
  • Run Connect-MSOLService and sign in with the Global Administrator account.
  • Run Set-MsolUser -UserPrincipalName ******@contoso.com -StrongAuthenticationMethods @() cmdlet to reset the MFA registration information.

Read More: Manage user authentication methods for Azure AD Multi-Factor Authentication

Hope this helps,
Carlos Solís Salazar

----------

Accept Answer and Upvote, if any of the above helped, this thread can help others in the community looking for remediation for similar issues.

NOTE: To answer you as quickly as possible, please mention me in your reply.


Was this answer helpful?

3 people found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.