Microsoft Authenticator - multiple devices?

Sonja Coulter 0 Reputation points
2026-09-03T08:16:18.67+00:00

How can I find out which device has the authenticator for an account? As IT admin in my school, many of the accounts for shared devices are authenticated on my phone, but there is one account used for substitute teachers that is not - and every time we try to log in to that account, it can't be authenticated because I don't know which device was used to set it up originally.

Can I find out which device?
Can I change the device used?
Or can I add another device?

Microsoft 365 and Office | Subscription, account, billing | For education | Other
0 comments No comments

2 answers

Sort by: Most helpful
  1. Demi Nguyen 1,505 Reputation points Independent Advisor
    2026-09-03T08:45:16.8533333+00:00

    Hello Sonja Coulter,

    Thank you for explaining the situation.

    The easiest approach would be to require the affected account to register MFA again. As the IT administrator, you can do this through the Microsoft Entra Admin Center:

    • Sign in to the Microsoft Entra Admin Center.
    • Go to Entra ID > Users.
    • Select the affected account.
    • Select Authentication methods.
    • Select "Require re-register MFA" and confirm the action.

    User's image

    The next time the account signs in, the user will be prompted to set up MFA again. You can then register Microsoft Authenticator on the device you want to use for that account.

    Please note that Require re-register MFA removes the account’s existing Microsoft Authenticator registrations, MFA phone numbers, and software OATH tokens. Please make sure this is the intended account before confirming the action.

    You can also refer to Microsoft’s official guidance here: Manage user authentication methods for Microsoft Entra multifactor authentication | Microsoft Learn

    I hope this helps you register the account on the appropriate device.

    Kind regards,


    If the answer is helpful, please click "Yes". If you have extra questions about this answer, please click "Comment". 

    Note: Please follow the steps in documentation to enable e-mail notifications if you want to receive the related email notification for this thread. 

    Was this answer helpful?


  2. AI answer

    2026-09-03T08:16:41.56+00:00

    For a work or school account, the practical way to identify and change Authenticator registrations is through the user’s Authentication methods and Security info entries.

    • Find which device is registered: Go to the user’s security info page at https://aka.ms/mysecurityinfo. The sign-in method list can show authenticator app methods associated with particular devices.
    • If too many or stale registrations exist: Delete old Authenticator sign-in methods from the user’s security info. This removes the stored device tokens tied to those registrations.
    • If the user cannot clean this up directly: As an admin, in Azure portalMicrosoft Entra IDUsers → select the user → Authentication methodsRequire re-register multifactor authentication. Then the account can re-register MFA on the correct device.
    • Add or change to another device: After cleanup or re-registration is required, sign in to the account’s Security info page, select Add sign-in method, choose Microsoft Authenticator, and complete the QR code setup on the new device.
    • If the old phone still receives prompts: Adding Authenticator on a new device does not automatically remove it from the old device. The old app/device must be removed from the account’s verification settings as well.
    • Push notifications on multiple devices: The available guidance confirms notifications work for work or school accounts only if the organization allows them. It does not provide a supported way here to keep the same work or school Authenticator approval active across multiple devices for the same registration. The supported path in this material is to remove old registrations and re-register the intended device.

    For the shared substitute-teacher account, the cleanest admin path is:

    1. Open the account in Microsoft Entra ID.
    2. Set Require re-register multifactor authentication.
    3. Have the account sign in again.
    4. Re-add Microsoft Authenticator on the intended phone from Security info.
    5. Remove any old Authenticator entries afterward.

    If the account has no alternate sign-in method and the current Authenticator prompt goes to an unknown device, re-registration by an admin is the documented recovery path.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.