Fix Microsoft Authenticator Requiring Approval from Old Device
Question details
The user is unable to sign in to a school-managed Microsoft 365 account because the authentication process is prompting for approval from a previously registered, now unavailable device.

- Product
- Microsoft 365 / Microsoft Authenticator
- Device & OS
- not provided
- Scenario
- Attempting to sign in to an account or register a new phone when the old device is lost, broken, or unavailable.
- Observed behavior
- The sign-in process halts and waits for approval from the old device's Authenticator app, completely blocking access to the account on the new device.
Before reaching out to support, check the sign-in screen for an 'I can't use my Microsoft Authenticator app right now' or 'Sign in another way' option to see if you previously set up a backup method like SMS or email verification.
Contact Your School's IT Administrator to Reset MFA
Because school-managed accounts have strict security policies, only an IT administrator can revoke your old device's access and allow you to register a new one.
Multifactor authentication (MFA) settings for educational institutions are managed centrally. When you lose access to your primary authentication device, the system locks you out to prevent unauthorized access. You cannot bypass this security measure on your own.
Your school's IT administrator has the tools to reset your authentication session in the Microsoft Entra admin center, which will clear the old device's approval requirement.
Find the contact information for your school's IT helpdesk or technical support team. This is usually found on your school's official website or student portal.
Contact the IT administrator and explain that you need to register a new phone for Microsoft Authenticator, but the system is asking for approval from an old device. Ask them to reset your multifactor authentication methods.
The administrator will log into the Microsoft Entra admin center, locate your user profile, and select 'Require re-register MFA' or revoke your existing MFA sessions.
Once the reset is confirmed, attempt to sign in to your Microsoft 365 account on your computer. You will be prompted to set up Microsoft Authenticator again. Follow the on-screen QR code instructions using your new phone.

Try WPS Office for a Hassle-Free Experience
Locked out of your Microsoft 365 account due to verification issues? Stay productive with WPS Office. It is a powerful, lightweight, and completely free alternative that lets you view, edit, and create documents locally without worrying about complex account lockouts or cloud verification barriers.
- 1. Download WPS Office: Visit the official WPS website and download the free version for your operating system.
- 2. Install and Launch: Follow the simple installation prompt, then open WPS Office to access Writer, Spreadsheets, and Presentation.
- 3. Open Your Files Seamlessly: Drag and drop your existing .docx, .xlsx, or .pptx files into WPS Office to continue your work without formatting loss.

Frequently Asked Questions
Why does Microsoft Authenticator keep asking for my old phone?
The Authenticator app uses a hardware-specific token tied to your previous device. When you try to log in, the Microsoft security system sends the prompt exclusively to that registered hardware to ensure the login attempt is genuinely yours.
Can I transfer Microsoft Authenticator to a new phone without the old one?
If you enabled cloud backup in the Authenticator app on your old phone and have a personal Microsoft account, you can recover credentials on your new phone. However, for school or work accounts, restoring from a backup often still requires you to re-verify using a secondary method or via an IT admin.
How long does it take for an IT admin to reset my authentication methods?
The actual process in the Microsoft Entra admin center takes only a few seconds. Once the IT administrator clicks 'Require re-register MFA', the changes take effect immediately, allowing you to set up your new phone right away.




