How to Recover a Locked Microsoft 365 Work Account Without MFA
Question details
A Microsoft 365 administrator needs to restore an employee's account access after they lose access to their MFA device or Microsoft Authenticator app.

- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- An employee's laptop or mobile device is locked or unavailable, preventing them from using the Microsoft Authenticator app to pass the multi-factor authentication prompt.
- Observed behavior
- The employee is permanently stuck at the MFA verification screen during sign-in, requiring an administrator to reset or bypass the current authentication method.
Ensure you are signed into the Microsoft Entra admin center with an account that has at least the Authentication Administrator or Global Administrator role.
Require MFA Re-registration via Microsoft Entra Admin Center
This is the most secure and recommended method. It clears the employee's old Authenticator app registration and forces them to configure a new MFA device on their next sign-in.
By requiring MFA re-registration, the system safely invalidates the inaccessible Authenticator app.
Note that this process only resets Microsoft 365 account access. If the employee is locked out of a physical Windows device, separate BitLocker or Windows recovery procedures will be necessary.
Open your web browser and sign in to the Microsoft Entra admin center using your administrator credentials.
In the left-hand navigation pane, expand the 'Identity' menu, click on 'Users', and then select 'All users'.
Use the search bar to find the employee who is locked out. Click on their name to open their profile page.
On the user's profile menu on the left, scroll down and click on 'Authentication methods'.
Click the 'Require re-register MFA' option at the top of the pane. Confirm the action. The employee can now sign in with their password and will be prompted to set up a new MFA method.

Looking for a Hassle-Free Office Suite? Try WPS Office
While resolving complex administration and cloud MFA lockouts in Microsoft 365, you might appreciate a simpler, lightweight office solution for your local tasks. WPS Office is a powerful, free alternative that offers seamless compatibility and offline capabilities without complicated login hurdles.
- 1. Download the Installer: Visit the official WPS Office website and click the free download button for your operating system.
- 2. Install WPS Office: Run the downloaded installation file and follow the simple on-screen instructions to set up the suite.
- 3. Start Creating Offline: Open WPS Writer, Spreadsheet, or Presentation to immediately start working on your documents without mandatory cloud logins.

Frequently Asked Questions
Can an employee reset their own MFA without the Authenticator app?
Generally, no. Unless the organization has previously configured and allowed alternative authentication methods (such as SMS or a secondary email) for self-service password reset (SSPR), an administrator must intervene to clear the MFA requirement.
What happens when an administrator clicks 'Require re-register MFA'?
This action removes the trusted status of the user's current Microsoft Authenticator app or device. The next time the user successfully enters their password, the system will prompt them to set up a new multi-factor authentication method from scratch.
How can I revoke existing MFA sessions for a compromised account?
In the Microsoft Entra admin center, navigate to the user's 'Authentication methods' page and select 'Revoke MFA sessions'. This will clear all remembered MFA sessions across all of the user's devices, forcing them to authenticate again.
Does resetting Microsoft 365 MFA unlock a BitLocker-encrypted laptop?
No. Resetting MFA in Entra only restores access to the cloud account. If the physical Windows device is locked with BitLocker, the administrator must separately retrieve the BitLocker recovery key from the Entra admin center's 'Devices' section.




