logo
search
list

Table of Content

Re-Register MFA When Microsoft Authenticator Is Unavailable

Posted by Algirdas Jasaitis

calendar

2026-08-30

views

871

likes

4

Fix Microsoft 365 Admin Lockout Without Authenticator

Locked out of your Microsoft 365 admin account because Authenticator is unavailable? Learn how to reset your MFA methods and regain tenant access.

Getting locked out of your Microsoft 365 administrative center because you lost access to your authentication app can be incredibly stressful, but there are official recovery paths to help you safely regain control of your tenant.

Problem Description: Lost Microsoft 365 MFA Access

This issue occurs when a Microsoft 365 or Microsoft Entra ID (formerly Azure AD) administrator is prompted to approve a sign-in request via the Microsoft Authenticator app, but the app is unavailable. This commonly happens if the user gets a new mobile device, accidentally uninstalls the application, or loses their phone without having a backup authentication method configured. Because administrative accounts enforce strict Multi-Factor Authentication (MFA) policies by default, the user is effectively locked out of the tenant.

Quick Answer for Admin Authenticator Lockouts

The fastest way to regain access is to ask another Global Administrator in your organization to reset your authentication methods via the Microsoft Entra admin center. If you are the only administrator for the tenant, you must contact Microsoft Data Protection Support directly to verify your identity and have them manually reset your MFA settings.

Likely Causes Behind Entra ID Authentication Failures

  • Device Replacement: Upgrading or replacing a smartphone without first transferring the Microsoft Authenticator tokens to the new device.
  • App Deletion: Accidentally deleting the Microsoft Authenticator app or wiping the mobile device.
  • Lack of Alternative Methods: Failing to set up secondary verification methods (like an alternate phone number or hardware token) during the initial MFA registration.
  • Strict Conditional Access: Tenant policies that strictly require Authenticator app push notifications, blocking SMS or voice call fallbacks.

Recommended Solution: Reset Entra ID MFA Methods

If your organization has more than one administrator, follow these steps to have your co-administrator reset your MFA configuration:

  1. Have an active administrator navigate to the Microsoft Entra admin center (entra.microsoft.com) and sign in.
  2. On the left-hand navigation menu, expand Identity, select Users, and then click on All users.
  3. Search for and select the account of the locked-out administrator.
  4. In the user's profile menu on the left, click on Authentication methods.
  5. Click on Require re-register MFA at the top of the pane. This invalidates the old app connection.
  6. Attempt to log into your Microsoft 365 admin account again. You will be prompted to register a new device with the Microsoft Authenticator app.

Alternative Solutions for Sole Global Administrator Recovery

If you are the only Global Administrator on the account, another user cannot reset your MFA. You must work directly with Microsoft:

  1. Call Microsoft Business Support for your specific country/region and ask to be routed to the Data Protection Team.
  2. Be prepared for a strict verification process. Microsoft will require proof of tenant ownership, such as domain DNS records or billing information.
  3. If you cannot create a support ticket because you cannot log in, you may need to create a temporary, free Microsoft 365 tenant to access the unified support portal and submit a ticket referencing your locked tenant's domain.
  4. Wait for the Data Protection team to investigate and securely clear your MFA settings. This process can take several days for security reasons.

Working with WPS Office: Managing Documents Offline

While WPS Office cannot resolve Microsoft Entra ID authentication lockouts, being locked out of your Microsoft 365 account means you lose access to cloud-based Word, Excel, and PowerPoint apps. If you need to urgently view, edit, or create business documents while waiting for Microsoft to unlock your account, WPS Office is an excellent free alternative. It offers full compatibility with Microsoft file formats (.docx, .xlsx, .pptx) and allows you to work seamlessly on local files without requiring a cloud login or subscription, ensuring your productivity isn't halted during an administrative lockout.

Prevention Tips for Future Admin Account Lockouts

  • Create a Break-Glass Account: Always maintain at least two Global Administrator accounts. One should be a dedicated emergency access account (break-glass account) that is excluded from conditional access policies requiring the Authenticator app, ideally secured with a physical FIDO2 security key.
  • Set Up Multiple Verification Methods: Require admins to register at least two MFA methods, such as the Authenticator app and a secure secondary phone number for SMS/voice fallback.
  • Backup Authenticator Credentials: Turn on cloud backup within the Microsoft Authenticator app on your mobile device so credentials can be easily recovered if the physical phone is lost.

FAQs About Microsoft 365 Tenant Authentication

How long does it take for Microsoft Data Protection to unlock an account?

Because of the severe security implications of resetting a Global Administrator's access, the verification and unlock process through the Microsoft Data Protection team can take anywhere from 24 hours to several weeks, depending on how easily you can prove domain ownership.

Can I bypass MFA if I have my administrator password?

No. By design, if Multi-Factor Authentication or Security Defaults are enabled on your Microsoft 365 tenant, having the correct username and password is not enough to bypass the MFA prompt. You must complete the secondary verification or have the requirement officially reset.

Algirdas Jasaitis

15 years of office industry experience, tech lover and copywriter. Follow me for product reviews, comparisons, and recommendations for new apps and software.