Microsoft 365 Admin Locked Out by Authenticator

2026-09-10T08:55:30.84+00:00

I am the Microsoft 365 administrator for our organization and I recently changed my phone.

I no longer have access to the Microsoft Authenticator app that was registered on my previous device. When I try to sign in to Microsoft 365, Microsoft Entra Admin Center or the Security Info page, I am asked to approve the sign-in or enter a code from Microsoft Authenticator.

The problem is that I cannot access the Authenticator for this account on my new phone because signing in to Authenticator itself also requires verification through the old Authenticator.

There are no alternative verification methods available for my account.

I still have access to some Microsoft 365 services on my laptop through an existing session but I cannot access the Admin Center or authentication settings because MFA is requested again.

I am also the administrator and therefore cannot reset my own MFA through the Admin Center.

Could you please advise what recovery options are available in this situation?

Specifically:

  • How can I reset or re-register Microsoft Authenticator if I cannot access the old device?
  • Is there a recovery process for an administrator who is locked out by MFA?
  • If I am the only administrator with the required privileges, how can I contact Microsoft to restore administrative access to the tenant?
  • Is there any way to use my existing authenticated session on the laptop to reset the MFA method?

Thank you for your guidance.

Microsoft 365 and Office | Subscription, account, billing | For business | Other
0 comments No comments

1 answer

Sort by: Most helpful
  1. Killian N 3,820 Reputation points Independent Advisor
    2026-09-10T09:44:45.8733333+00:00

    Hi Владислав,

    From what you've described, it sounds like your Multi-Factor Authentication (MFA) setup may need to be reset. This can sometimes happen after switching to a new device, replacing a phone, or reinstalling the Microsoft Authenticator app. Since your new device hasn't been registered yet, the authentication requests may still be linked to your previous device, which can leave you stuck in a sign-in loop.

    And regarding your questions:

    1. Reset/re-register Authenticator: Since you do not have access to the old device and appear to be the only admin, Microsoft support will need to assist with resetting your MFA methods.
    2. Admin MFA recovery: Yes. Microsoft's Data Protection team can help recover access after verifying tenant ownership.
    3. Contacting Microsoft: Since you cannot access the Admin Center, you'll need to contact Microsoft support directly or work with your reseller/partner to open a support request on your behalf.
    4. Using the existing laptop session: Generally no. Resetting MFA typically requires a new authentication challenge, so an existing session usually cannot be used to re-register Authenticator.

    If your account is also an admin account and there are no other available global administrators in your tenant, then the only way to regain access is contact Microsoft support. Please try locating the appropriate hotline for your region here: Customer service phone numbers - Microsoft Support  

    In this situation, the Microsoft Data Protection team has tools and processes in place to verify identity and regain access to administrator accounts.  

    Here are some tips and an example of a prompt to help you navigate the IVR more effectively:  

    (When you call the support number, you may hear an introduction of about 30 seconds such as "you can visit the link...". You can ignore this introduction and wait until you are presented with the options. Then press "1" as a business email user, and again "1" for technical help.)    

    In some regions, the initial interaction may be automated, so here’s a general idea of how the conversation might go to help you prepare:      

    • What kind of problem are you experiencing?         
    • Answer: Authenticator         
    • What products do you use?         
    • Answer: Office 365 for business         
    • Is this for an education or company account?         
    • Answer: For companies         
    • Are you an administrator?         
    • Answer: Yes         
    • Are there any other administrators in your organization?         
    • Answer: No. I am the only admin in my tenant          
    • Do you need a... Service request?          
    • Answer: Yes. I need to create a ticket. Please send me direct to the Data Protection Teams.      

    During the phone call, you will need to provide the information associated with your subscription, such as your company name, billing details, phone number, and an alternate email address, etc. This information allows the Data Protection team to verify your identity and securely assist you in regaining access to your administrator account.      

    In case you are unable to contact the frontline support: 

    Consider signing up for a trial subscription to create a new tenant. Once set up, you can access the new tenant's admin console and submit a support ticket to speak with the data protection team on behalf of the previous tenant. Once your issue is resolved, please remember to cancel the trial subscription to avoid any unintended charges. 

    If your organization's subscription is from a partner or reseller: Contact the reseller's support provider to help open a service request on behalf of you instead. 

    I hope this helps point you in the right direction. If you have any updates or additional questions, feel free to reply back and I'll do my best to assist further. 

    Best regards, 

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.