logo
search
MFA & Verification Issues

How to Recover a Locked Microsoft 365 Work Account Without MFA

Nimra MalikNimra Malik Sep 28, 2026 869 views

Question details

A Microsoft 365 administrator needs to restore an employee's account access after they lose access to their MFA device or Microsoft Authenticator app.

How to Recover a Locked Microsoft 365 Work Account Without an MFA Device
Product
Microsoft 365
Device & OS
not provided
Scenario
An employee's laptop or mobile device is locked or unavailable, preventing them from using the Microsoft Authenticator app to pass the multi-factor authentication prompt.
Observed behavior
The employee is permanently stuck at the MFA verification screen during sign-in, requiring an administrator to reset or bypass the current authentication method.
Before you start

Ensure you are signed into the Microsoft Entra admin center with an account that has at least the Authentication Administrator or Global Administrator role.

Solution 1Recommended

Require MFA Re-registration via Microsoft Entra Admin Center

This is the most secure and recommended method. It clears the employee's old Authenticator app registration and forces them to configure a new MFA device on their next sign-in.

By requiring MFA re-registration, the system safely invalidates the inaccessible Authenticator app.

Note that this process only resets Microsoft 365 account access. If the employee is locked out of a physical Windows device, separate BitLocker or Windows recovery procedures will be necessary.

1
Sign in to Microsoft Entra

Open your web browser and sign in to the Microsoft Entra admin center using your administrator credentials.

2
Navigate to All Users

In the left-hand navigation pane, expand the 'Identity' menu, click on 'Users', and then select 'All users'.

3
Select the Employee Account

Use the search bar to find the employee who is locked out. Click on their name to open their profile page.

4
Open Authentication Methods

On the user's profile menu on the left, scroll down and click on 'Authentication methods'.

5
Require Re-register MFA

Click the 'Require re-register MFA' option at the top of the pane. Confirm the action. The employee can now sign in with their password and will be prompted to set up a new MFA method.

Require MFA Re-registration via Microsoft Entra Admin Center
Session Revocation: If you suspect the employee's account or old device is compromised, you can also click 'Revoke MFA sessions' on the same screen to immediately sign them out of all devices.
Free Microsoft Office alternative

Looking for a Hassle-Free Office Suite? Try WPS Office

While resolving complex administration and cloud MFA lockouts in Microsoft 365, you might appreciate a simpler, lightweight office solution for your local tasks. WPS Office is a powerful, free alternative that offers seamless compatibility and offline capabilities without complicated login hurdles.

  1. 1. Download the Installer: Visit the official WPS Office website and click the free download button for your operating system.
  2. 2. Install WPS Office: Run the downloaded installation file and follow the simple on-screen instructions to set up the suite.
  3. 3. Start Creating Offline: Open WPS Writer, Spreadsheet, or Presentation to immediately start working on your documents without mandatory cloud logins.
Fully compatible with Microsoft Word, Excel, and PowerPoint formats (.docx, .xlsx, .pptx).Work offline locally without being blocked by complex MFA or cloud-only login requirements.Lightweight installation with a familiar, easy-to-use tabbed interface.Built-in PDF editing, merging, and conversion tools included for free.
microsoft office alternative - wps office

Frequently Asked Questions

Can an employee reset their own MFA without the Authenticator app?

Generally, no. Unless the organization has previously configured and allowed alternative authentication methods (such as SMS or a secondary email) for self-service password reset (SSPR), an administrator must intervene to clear the MFA requirement.

What happens when an administrator clicks 'Require re-register MFA'?

This action removes the trusted status of the user's current Microsoft Authenticator app or device. The next time the user successfully enters their password, the system will prompt them to set up a new multi-factor authentication method from scratch.

How can I revoke existing MFA sessions for a compromised account?

In the Microsoft Entra admin center, navigate to the user's 'Authentication methods' page and select 'Revoke MFA sessions'. This will clear all remembered MFA sessions across all of the user's devices, forcing them to authenticate again.

Does resetting Microsoft 365 MFA unlock a BitLocker-encrypted laptop?

No. Resetting MFA in Entra only restores access to the cloud account. If the physical Windows device is locked with BitLocker, the administrator must separately retrieve the BitLocker recovery key from the Entra admin center's 'Devices' section.