logo
search
list

Table of Content

Utilize an Alternate Authentication Method
Reset User MFA Sessions via Microsoft Entra ID
Restore Global Administrator Access
Maintain Document Productivity with WPS Office During a Lockout
Frequently Asked Questions

How to Fix Tenant Access Locked Due to Inaccessible MFA Device in Microsoft Authenticator

Posted by Huda Qurayshi

calendar

2026-09-08

views

869

likes

4

Losing access to the Microsoft Authenticator app can immediately lock you out of your organization's Microsoft 365 or Azure tenant. When the device hosting your multi-factor authentication tokens is lost, broken, replaced, or wiped, the standard sign-in loop halts. Because Conditional Access policies demand a secondary token that you can no longer generate, you cannot access company emails, admin portals, or cloud documents. This guide provides the exact diagnostic steps and recovery workflows to bypass the inaccessible application and restore your tenant privileges, depending on your account's permission level.

Utilize an Alternate Authentication Method

Illustrated steps for Fixing Tenant Access Locked Due to Inaccessible MFA Device in Microsoft Authenticator
Key actions for Fixing Tenant Access Locked Due to Inaccessible MFA Device in Microsoft Authenticator.

Before escalating the issue to an administrator, check if a secondary verification method is actively attached to your Microsoft profile. The system allows you to route around the primary app if you previously configured a fallback mechanism.

  • Step 1: Navigate to the Microsoft 365 sign-in page and enter your standard username and password.
  • Step 2: When the prompt appears asking you to approve the sign-in via the app or enter a code, look for the Sign in another way link at the bottom of the dialogue box. Click it.
  • Step 3: A list of your registered fallback methods will appear. Select an available alternative, such as receiving a code via an SMS text message, a voice call to a registered phone number, or utilizing a hardware FIDO2 security key.
  • Step 4: Enter the verification code you receive.
  • Step 5: Once successfully authenticated, immediately navigate to your My Security Info dashboard (mysignins.microsoft.com/security-info). Delete the old device from the list of authentication methods and click Add sign-in method to register your new device.

Reset User MFA Sessions via Microsoft Entra ID

If you are a standard user without backup methods, you cannot bypass this security mechanism alone. You must contact your organization's IT department. If you are the IT administrator resolving this for a locked-out employee, here is the exact workflow to clear the old device requirement using the Microsoft Entra admin center.

  • Step 1: Log into the Microsoft Entra admin center (entra.microsoft.com) using an account with at least Authentication Administrator privileges.
  • Step 2: Expand the Identity menu on the left sidebar, click Users, and select All users.
  • Step 3: Use the search bar to find the locked-out user's profile and click on their display name to open the user blade.
  • Step 4: In the left navigation pane under the user's specific profile menu, click Authentication methods.
  • Step 5: Click the Require re-register MFA button located in the top command bar. This specific action strips the current app binding and forces the system to ask for a new registration upon the next login.
  • Step 6: Click Revoke MFA sessions immediately next to it. This clears any cached tokens that might cause the login loop to persist on the user's browser.

The expected result is that the next time the user attempts to log in, they will be greeted with a "More information required" screen, guiding them to scan a new QR code with their new device.

Restore Global Administrator Access

If you are the sole Global Administrator for the tenant and your device is unavailable, the entire tenant is locked. Standard administrative portals will not work because your own account is trapped by Conditional Access. You have two potential recovery paths.

Method 1: The Emergency Access Account
If you followed administrative best practices, you previously configured a "break-glass" account. This is a cloud-only account (ending in .onmicrosoft.com) that is explicitly excluded from Conditional Access MFA policies. Log into the Entra admin center using these emergency credentials. Once inside, navigate to your primary global admin account and follow the re-registration steps outlined in the previous section to unlock yourself.

Method 2: Microsoft Data Protection Team
If no emergency account exists, you must engage the Microsoft Data Protection team. Call the Microsoft business support line specific to your region. Navigate the automated phone tree by stating you are experiencing a "Global Admin account lockout." You will be routed to a specialized engineering team. They will require you to add specific DNS TXT records to your domain's public DNS host (e.g., GoDaddy, Cloudflare) to prove domain ownership. Once verified, the engineers will manually sever the multi-factor authentication connection to your tenant. This process typically takes between 48 hours and two weeks to complete.

Maintain Document Productivity with WPS Office During a Lockout

WPS Office options related to Fixing Tenant Access Locked Due to Inaccessible MFA Device in Microsoft Authenticator
How WPS Office can support related document work.

While waiting for IT or the Microsoft Data Protection team to unlock your tenant, your local Microsoft 365 desktop applications may enter a reduced functionality mode if they fail to sync with the licensing server. WPS Office cannot alter your Microsoft Entra ID settings, change Conditional Access policies, or recover your locked tenant account; however, it provides an immediate offline workflow to continue working on your local business files without requiring a Microsoft tenant login.

If Microsoft Word or Excel blocks editing features due to an unverified license state during your lockout, you can open your local .docx, .xlsx, and .pptx files directly in WPS Office. Because WPS Office operates independently of Microsoft 365 cloud licensing, you can continue to edit, format, and save your documents locally on your hard drive.

Use the WPS Writer application to draft time-sensitive reports or WPS Spreadsheet to finalize local data analysis without dealing with the blocked sign-in prompts. Once your tenant access is fully restored and your new app is functional, you can seamlessly upload the newly saved files from WPS Office back into your company's SharePoint or OneDrive directories.

100% secure

Frequently Asked Questions

Why does the authenticator app not sync my accounts when installed on a new phone?

The app relies on a specific cloud backup feature that must be manually enabled on the original device. If you did not toggle on "Cloud Backup" (iOS) or "Cloud Sync" (Android) in the app settings before losing the device, the new installation will not automatically import your tenant tokens, resulting in a locked access state.

Can I bypass the prompt by resetting my Microsoft account password?

No. Password resets only change the primary authentication factor. Conditional Access policies enforce the secondary factor entirely independently. Even if you successfully reset and enter a new password, the system will immediately demand the verification code from your unavailable device.

How long does Microsoft Support take to unlock a sole global admin account?

For single-admin tenants, the Data Protection team typically takes between two days and two weeks to verify domain ownership and reset the multi-factor authentication requirements. This extended delay is a strict security measure designed to prevent unauthorized social engineering attacks against enterprise tenants.

Will removing the old device from my Microsoft account fix the login loop?

Yes, but you can only remove the device if you can successfully log into the Security Info portal using an alternate verification method. If you are entirely locked out and have no fallback methods, you cannot reach the page to remove the device. In that scenario, an administrator must intervene via the Entra ID portal to revoke the active sessions on your behalf.

Huda Qurayshi

Expert in office suites and technology with a strong background in writing. I specialize in reviewing public health topics, delivering insightful, accurate content for diverse audiences in tech.