How to Reset Microsoft Authenticator Without App Access for Admins
Question details
The user needs to recover or reset the Microsoft Authenticator setup for an organization's administrator account after the person who configured it left the company.
- Product
- Microsoft Authenticator
- Device & OS
- not provided
- Scenario
- The previous IT administrator left the organization, taking away the only device with the Microsoft Authenticator app configured for the main admin account.
- Observed behavior
- The user is unable to log in to the admin account because MFA is required. Contacting phone support redirects the user to a support page that ironically requires administrator access to view, creating a login loop.
Check if there is another active Global Administrator in your Microsoft 365 or Azure tenant, as they can easily reset your MFA methods from the admin center without requiring Microsoft Support.
Request Account Recovery via Microsoft Q&A Community
Since phone support requires admin access, posting in the specialized Microsoft Q&A community is the best way to flag the issue to a Microsoft Data Protection representative.
When an organization loses its sole global administrator, standard support channels often result in a loop because they require you to log in to create a ticket. Microsoft's community forums are monitored by technical staff who can initiate a secure tenant recovery process.
Open your web browser and navigate to the official Microsoft Q&A platform (learn.microsoft.com/en-us/answers).
Search for the 'Microsoft Authenticator' tag to ensure your question reaches the right technical experts.
Click 'Ask a question' and clearly state that the sole administrator has left the organization and you are locked out of the tenant due to MFA.
A Microsoft representative will typically reply and move the conversation to a private message to verify your identity and organizational ownership before resetting the admin MFA.
Consult the Official Microsoft Authenticator FAQs
Review the official documentation for specific procedures regarding lost devices and administrator recovery.
Maintain Productivity Without Admin Hurdles Using WPS Office
While you are waiting to recover your Microsoft administrator account, your team still needs to get work done. WPS Office is a free, lightweight, and user-friendly alternative that requires no complex administrative setups or mandatory MFA for basic offline editing, all while offering seamless migration.
- 1. Download the Installer: Visit the official WPS website and download the free installation package for your operating system.
- 2. Install the Software: Run the installer and follow the simple on-screen instructions. No IT admin privileges are required for basic user-level installation.
- 3. Open Your Office Files: Launch WPS Office and directly open your existing .docx, .xlsx, or .pptx files to continue working seamlessly.

Frequently Asked Questions
Can another administrator reset my Microsoft Authenticator setup?
Yes. If your organization has more than one Global Administrator or Authentication Administrator, the other admin can log into the Microsoft Entra ID admin center, navigate to your user profile, and click 'Require re-register MFA'. This allows you to set up the app on a new device.
What happens if the only administrator loses access to the Authenticator app?
If the sole administrator loses access, you are in a 'tenant lockout' scenario. You must contact Microsoft Support (specifically the Data Protection team) and provide legal proof of domain and business ownership to have the MFA requirement bypassed.
Can I bypass Microsoft Authenticator if I lose my phone?
If you previously set up alternative verification methods (like SMS, a phone call, or a secondary email), you can click 'Sign in another way' on the login screen to bypass the app. If no alternative methods were set up, you cannot bypass it yourself.
How can I prevent losing access to Microsoft Authenticator in the future?
To prevent lockout, always configure 'Cloud Backup' in the Microsoft Authenticator app settings. Additionally, organizations should ensure they have at least two designated Global Administrator accounts (often called 'break-glass' accounts) to prevent a single point of failure.




