How to Reset MFA for a Former Employee's Microsoft Account
Question details
An organization needs to regain access to a Microsoft account that is still linked to a former employee's personal phone for multi-factor authentication.

- Product
- Microsoft 365 / Entra ID
- Device & OS
- not provided
- Scenario
- Employee turnover and administrative account recovery
- Observed behavior
- The organization is blocked from logging into the account because the multi-factor authentication prompt is sent to a device they no longer control.
Ensure you are logged in with an account that has Global Administrator, Privileged Authentication Administrator, or Authentication Administrator privileges in your Microsoft Entra ID environment.
Reset Authentication Methods via Microsoft Entra ID Admin Center
Use the administrative recovery process in Microsoft Entra ID to invalidate the former employee's device and force a new MFA registration.
Community moderators and Microsoft Support cannot bypass two-factor authentication for user accounts due to strict security policies. The only authorized way to clear the old phone requirement is through your organization's administrative recovery procedures.
Log in to the Microsoft Entra admin center (or Microsoft 365 admin center) using your administrator credentials.
Navigate to 'Identity' > 'Users' > 'All users' in the left-hand menu, and use the search bar to find the former employee's account.
Click on the user's name to open their profile details, then select 'Authentication methods' from the left navigation pane.
Click on the 'Require re-register MFA' option at the top of the pane. This will invalidate the old phone and prompt for a new MFA setup the next time someone logs into the account.

Manage Your Organization's Documents with WPS Office
While resolving your administrative access in Microsoft 365, consider WPS Office as a lightweight, cost-effective alternative for your team's document creation and collaboration needs. It offers an intuitive interface that ensures seamless migration for new and former employees alike.
- 1. Visit the Official Website: Navigate to the official WPS Office website to access the secure download page.
- 2. Download and Install: Click the 'Free Download' button for your operating system and follow the installation prompts.
- 3. Open Your Documents: Launch WPS Office and instantly open your existing Microsoft Office files without formatting loss.

Frequently Asked Questions
Can Microsoft Support bypass MFA for a former employee's account?
No. Microsoft Support and community moderators cannot bypass security protocols or disable MFA on behalf of users. Only your organization's internal IT administrator can reset the authentication methods.
What if the only global administrator leaves the company and their MFA is required?
If the sole global administrator leaves without transferring access, you must use Microsoft's account recovery process for administrators, which typically involves verifying domain ownership and company identity through the Microsoft Data Protection team.
How do I prevent this MFA lockout issue with future employees?
Implement a strict offboarding checklist that requires IT to reset passwords, revoke active sessions, and remove personal authentication methods before an employee departs. Using company-managed devices or hardware security keys for MFA also mitigates this risk.




