Share via

Microsoft 365 admin center - Unable to login by verifying using SMS

Phill Hayman 165 Reputation points
2026-05-13T00:53:46.4066667+00:00

Good morning!

We're unable to log into our Microsoft 365 tenant's Admin Center because verifying using SMS is not working. The system claims the account is not verified but doesn't allow any other options (error Code 399287).

I found in a few other post this can be solved by the engineering team, so I'm tagging the person from Microsoft that was able to get this fixed: @Raja Pothuraju , could you do the same for me?

Kind regards,

Phill H

Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Most helpful
  1. Q&A Assist
    2026-05-13T00:53:59.9633333+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    Error code 399287 indicates that the phone number used for SMS has been flagged with a “bad reputation” and is blocked for Microsoft Entra multifactor authentication. When this happens, SMS verification will fail and, if no other MFA methods are configured, access to the admin account can be blocked.

    Forum moderators and community engineers cannot directly fix this; the issue must be handled by Microsoft support/Data Protection.

    Use the following approach:

    1. If there is another global admin
      • Sign in with another global admin account (if available).
      • In the Azure portal, go to Microsoft Entra ID → Users → select the affected admin.
      • Check if Block sign in is enabled; if so, disable it.
      • Reset the user’s MFA methods and add an alternative method (such as Microsoft Authenticator or another phone number) so sign-in does not depend on the blocked SMS number.
    2. If this is the only admin account
      • Contact Microsoft support and ask specifically for the Microsoft 365 Data Protection team to assist with admin account recovery and MFA reset. They have internal tools to:
        • Clear the “bad reputation”/block on the phone number, or
        • Reset MFA for the locked global admin so a new method can be configured.
      • If direct support access is not possible because sign-in is blocked, create a new temporary Microsoft 365 trial tenant, go to admin.microsoft.com → Support → Help & support, and open a service request from there. Clearly state that:
        • This is a different tenant used only to contact support.
        • The problem is with a separate production tenant where the only global admin is locked out due to SMS MFA error 399287.
      • Provide the affected tenant domain, the admin UPN, the error code (399287), and that SMS MFA is the only configured method.
    3. After support resets MFA or clears the block
      • Sign in to the admin account.
      • Immediately configure multiple MFA methods (Microsoft Authenticator app, an additional phone number, possibly security keys) to avoid being locked out again if SMS fails.

    The actual unblock/reset for error 399287 can only be completed by Microsoft support/Data Protection; community tagging of individual engineers is not sufficient to resolve it.


    References:

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.