logo
search
list

Table of Content

Microsoft-aanmeldfout 500121 door Authenticator en MFA oplossen

Posted by Algirdas Jasaitis

calendar

2026-08-30

views

868

likes

59

Fix Microsoft Login Error 500121 (MFA & Authenticator)

Learn how to resolve Microsoft error code 500121. Discover steps for IT admins and users to reset MFA registrations and fix Authenticator login issues.

Being locked out of your work or school account due to an authentication error can be incredibly frustrating, but restoring your access is usually a straightforward process with the right administrative steps.

Problem Description: Microsoft MFA Authentication Failure

Error code 500121 occurs when a user attempts to sign into a Microsoft work or school account and fails the Multi-Factor Authentication (MFA) challenge. This issue prevents access to Microsoft 365 services and typically stems from a breakdown in communication between the Microsoft Authenticator app and the organization's identity security policies.

Quick Answer for Resolving Code 500121

To fix this immediately, contact your IT administrator and ask them to execute the "Require re-register MFA" command for your account in Microsoft Entra ID. Afterward, delete the old profile in your Authenticator app and set it up again.

Likely Causes Behind Entra ID Login Blocks

  • Outdated Authenticator Registration: The device or app was changed, updated, or restored without migrating the security tokens properly.
  • Conditional Access Policies: A recent change in your organization's IT security rules is blocking your specific device, IP address, or login location.
  • Corrupted MFA Tokens: The authentication session token has expired or become corrupted in the browser or application cache.
  • Device Status: Your computer or mobile device may no longer be marked as "Compliant" in Microsoft Intune or Entra ID.

Recommended Solution: Resetting Authenticator Registration

  1. Contact IT Support: Reach out to your organization's IT administrator, as this primary fix requires tenant-level administrative privileges.
  2. Check Sign-in Logs (For Admins): The admin should log into the Microsoft Entra admin center, navigate to Sign-in logs, and review the exact Conditional Access policy or MFA step causing the failure.
  3. Require MFA Re-registration (For Admins): The admin must go to Users > select the affected user > Authentication methods, and click Require re-register MFA.
  4. Clear Old App Data (For Users): Open the Microsoft Authenticator app on your smartphone, locate your work/school account, and delete the existing invalid profile.
  5. Reconfigure MFA (For Users): Sign in to your Microsoft account on a web browser. You will be prompted to "Provide more information." Follow the on-screen steps to scan the new QR code and add the account back to your Authenticator app.
  6. Global Admin Lockout: If you are the sole Global Administrator and are locked out by this error, you must contact Microsoft Data Protection Support via phone to verify your identity and regain administrative access.

Alternative Solutions for Authentication Glitches

  1. Use an Alternative Method: If you previously registered a backup MFA method (like an SMS code, voice call, or FIDO2 security key), click "Sign in another way" on the login screen to bypass the Authenticator app temporarily.
  2. Check Device Date and Time: Ensure your mobile device's clock is set to sync automatically. Time desynchronization can cause time-based authentication codes and push notifications to fail.
  3. Clear Browser Cache: If trying to log in via a web browser, clear your cookies and cache, or try signing in using an Incognito/Private browsing window to ensure old login tokens aren't causing conflicts.

Working with WPS Office: A Reliable Offline Alternative

Since error 500121 is strictly a Microsoft cloud authentication issue, WPS Office cannot fix the Entra ID login block itself. However, if you are locked out of Microsoft 365 and need to urgently complete your work, WPS Office serves as an excellent, free productivity alternative. You can use it to open, edit, and save your local Word, Excel, and PowerPoint documents without requiring any cloud authentication or MFA hurdles. Once your IT team resolves your Microsoft login, you can seamlessly upload your finished WPS documents back to OneDrive or SharePoint.

Prevention Tips for Future MFA Lockouts

  • Register Backup Methods: Always set up at least two authentication methods (e.g., the Authenticator app AND a trusted phone number) in your Microsoft security settings.
  • Use the Backup Feature: Enable cloud backup within the Microsoft Authenticator app so you can easily recover your credentials if you lose, wipe, or replace your phone.
  • Don't Delete Prematurely: Never delete the Authenticator app or your account profile from your old phone until you have successfully set it up and verified it on your new mobile device.

FAQs About Microsoft Error 500121

Can I fix error 500121 without an IT administrator?

Generally, no. Unless you have a secondary authentication method already set up that allows you to bypass the Authenticator app, you will need an IT admin to revoke your old MFA sessions and allow your account to re-register a new device.

Why did this error happen suddenly?

This authentication mismatch often occurs immediately after a smartphone software update, migrating data to a new phone, a password change, or when an IT admin updates organizational Conditional Access security policies.

Algirdas Jasaitis

15 years of office industry experience, tech lover and copywriter. Follow me for product reviews, comparisons, and recommendations for new apps and software.