A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
The mismatch usually means the sign-in is expecting a work or school account method, while Microsoft Authenticator is showing a personal Microsoft account code.
Supported facts from the current behavior:
- Azure sign-in can use number matching or a 6-digit code for work or school account verification.
- If Authenticator only shows an 8-digit code, that commonly aligns with a personal Microsoft account entry rather than the work/school account entry expected by Azure.
- If the number prompt does not appear, common causes include the app being locked, notifications being disabled or silent, an outdated app, or network/device time issues.
Try these steps in order:
- Check whether the Azure sign-in is using the correct account type
- If a choice appears between personal and work/school, select the work or school account path.
- If this account was previously tied to an employer tenant, Azure may still be using that organization’s MFA configuration.
- Try notification-based sign-in correctly
- On the sign-in page, select Send notification.
- If needed, select Other ways to sign in > Approve a request on my Microsoft Authenticator app.
- Open Authenticator on the phone or tap the New sign-in request notification.
- If prompted, enter or tap the matching number, then approve.
- Fix cases where the number prompt never appears
- Unlock the Authenticator app.
- In Authenticator, go to Settings and make sure notifications are enabled.
- Make sure the phone has internet access; try switching between Wi‑Fi and mobile data.
- Make sure Airplane mode is off.
- Check that the device Date & time are correct.
- If using a VPN, disconnect it and test again.
- Update Microsoft Authenticator to the latest version.
- If Azure asks for a 6-digit code but Authenticator only has 8 digits
- The Authenticator entry being used is likely not the correct work or school account registration for that Azure sign-in.
- If the account belongs to or was invited into an organization tenant, the tenant administrator may need to reset the Microsoft Authenticator registration.
- If completely locked out
- For a work or school account, contact the IT admin.
- For a personal account, send logs from Authenticator using Send feedback in the app, then contact Support.
- If this is a tenant lockout and no other global admin can sign in, the accepted resolution in similar Azure cases is a support ticket so the Data Protection team can help restore access.