Fix Microsoft Authenticator Requesting MFA for Old Alias Account
Question details
Users are being prompted by Microsoft Authenticator to provide MFA for an older, unregistered email alias when trying to access a SharePoint site hosted in an external tenant.
- Product
- Microsoft Authenticator / SharePoint
- Device & OS
- not provided
- Scenario
- Accessing a SharePoint site in an external tenant using a current email account, but the system mistakenly prompts for MFA on an outdated alias.
- Observed behavior
- The authentication fails or stalls because the requested MFA verification targets an old @domain2.com alias that is not set up or registered in the user's Microsoft Authenticator app.
Ensure you have the contact information for the IT administrator of the external SharePoint tenant, as this issue requires administrative access in the host directory to resolve.
Contact the External SharePoint Administrator
The most effective way to resolve alias mismatches is by having the external tenant administrator update your guest account configuration in their directory.
Because the SharePoint site is hosted in another organization's tenant, their Microsoft Entra ID (Azure AD) still holds your outdated alias as your primary guest identity. You cannot change this from your own account settings.
Contact the IT support desk or the administrator of the organization that is hosting the SharePoint tenant you are trying to access.
Ask the administrator to locate your guest account properties within their Microsoft Entra ID portal.
Request that they remove the outdated alias and ensure your primary current account is set as the correct sign-in identity.
Have the administrator select the 'Require re-register MFA' option for your guest profile. This will allow you to set up Microsoft Authenticator freshly with your current account upon your next login.
Seek Specialized Assistance from Microsoft Forums
If administrative resets do not completely resolve the issue, consult the official Microsoft Authenticator community for specialized troubleshooting.
Try WPS Office for Seamless Document Collaboration
While waiting for your Microsoft Authenticator and SharePoint access issues to be resolved, you can use WPS Office to create, edit, and collaborate on your documents. WPS Office is a lightweight, fully compatible alternative that works effortlessly with major Office file formats without requiring complex tenant authentication.
- 1. Download and Install: Visit the official WPS website to download and install the free WPS Office suite on your device.
- 2. Open Your Documents: Launch WPS Office and open your existing .docx, .xlsx, or .pptx files directly to continue your work offline or via WPS Cloud.
- 3. Collaborate and Share: Use the built-in sharing features to generate links and collaborate with your team without needing complex SharePoint guest access.

Frequently Asked Questions
Why does SharePoint ask for MFA on my old email alias?
When you were originally added as a guest to the external tenant, your old alias was recorded. The external tenant's directory still retains this outdated identity for your guest account, even if you updated it on your own end.
Can I fix the old alias MFA issue directly from my Authenticator app?
No. The authentication requirement is being strictly enforced by the external organization's directory policies. Their administrator must update your profile or reset your MFA status on their side.
How do I re-register my MFA for a SharePoint guest account?
Once the external administrator selects 'Require re-register MFA' for your guest profile in their admin center, you will automatically be prompted to set up Microsoft Authenticator again the next time you log into their SharePoint site.




