Losing access to your workplace environment halts productivity immediately. Whether you upgraded your mobile device, accidentally deleted the Microsoft Authenticator app, or lost your phone, being trapped in a Multi-Factor Authentication (MFA) loop requires specific routing to resolve. Because business environments are centrally managed, the exact workflow to regain access depends entirely on your permission level within the organization's directory.
Using Alternative Authentication Methods

Before escalating the issue to an administrator, you should check if your profile was configured with secondary verification options. Often, users set up an SMS number or an alternate email during their initial onboarding but forget to use it when the primary app is unavailable. When figuring out recovering a Microsoft 365 Business Account Locked by MFA as a standard employee, this is the only self-service route available.
To test alternative methods, navigate to the portal.office.com sign-in page and enter your business email and password. When the screen prompts you to approve the sign-in request on your authenticator app, do not look for the code. Instead, click the link labeled I can't use my Microsoft Authenticator app right now or Sign in another way located directly below the code entry field. If you previously registered a backup method, a new menu will appear listing options such as texting a code to your mobile phone or calling your registered office number. Select the SMS option, enter the code you receive into the browser, and you will bypass the app requirement. If no alternative options appear in this menu, your account strictly requires administrator intervention.
Resetting MFA as an Administrator
If an employee cannot bypass the prompt themselves, a global administrator or privileged authentication administrator must reset their connection. The fastest method for recovering a Microsoft 365 Business Account Locked by MFA is to force the system to drop the old device binding and require the user to register a new one upon their next login. This is done through Microsoft Entra ID (formerly Azure Active Directory).
Log into the Microsoft Entra admin center (entra.microsoft.com) using your administrator credentials. On the left-hand navigation menu, expand the Identity dropdown, click on Users, and then select All users. Use the search bar to locate the locked-out employee's profile and click on their display name to open their account dashboard. From the left menu of their profile, click on Authentication methods.
In the top command bar, click the Require re-register MFA button. A confirmation notification will appear at the top right of your screen. For good measure, click Revoke MFA sessions right next to it, which immediately invalidates any existing authentication cookies on the user's devices. Instruct the employee to log into Microsoft 365 on a private or incognito browser window. They will be greeted with a "More information required" screen, prompting them to scan a new QR code with their fresh authenticator app.
Escalating a Sole Administrator Lockout
The most difficult scenario occurs when the only global administrator for a small business tenant loses their MFA device. Because there is no higher-level admin to force a re-registration, you cannot fix this through the portal. Understanding the process of recovering a Microsoft 365 Business Account Locked by MFA in this specific situation requires interacting directly with Microsoft's internal security teams.
You must call the Microsoft Business Support phone number for your specific region. When the automated system answers, state that you need "Technical Support for Microsoft 365 Business" and specifically request the Data Protection Team. Standard frontline support agents do not have the authorization to bypass tenant security. Once you reach a Data Protection agent, they will open a security ticket.
To prove you own the tenant, the agent will send an email to your backup address with a specific TXT record string (e.g., MS=ms12345678). You must log into your domain hosting provider (such as GoDaddy, Cloudflare, or Namecheap), navigate to your DNS management zone, and add this TXT record. Once the DNS propagates, the Data Protection team will verify the record and manually unbind the MFA requirement from your admin account, allowing you to log in with just your password and set up a new device.
Documenting Emergency Procedures with WPS Office

WPS Office cannot access Microsoft Entra ID or alter your Microsoft authentication configurations in the cloud. However, after you successfully learn recovering a Microsoft 365 Business Account Locked by MFA, you must document a "Break-Glass" Standard Operating Procedure (SOP) and safely store offline backup codes to prevent a recurrence. Managing these sensitive recovery documents offline is a task where WPS Office excels.
You can use WPS Writer to draft your company's emergency access procedures and secure them before storing them on a local, offline drive. Open WPS Writer and create a new document outlining your tenant's Microsoft support numbers, domain host logins, and emergency backup codes. To ensure this file remains secure from unauthorized local access, click the Review tab on the top ribbon, then select Protect. Choose Document Encryption from the dropdown. Enter a complex alphanumeric password in the "Password to open" field and confirm it. Save the file as a standard DOCX or output it as a PDF using the Export to PDF tool under the Home tab. The resulting encrypted file will require the password before anyone can read your MFA recovery codes, providing a secure, offline failsafe.
FAQs
Can a standard user bypass the authenticator app requirement without admin help?
A standard user can only bypass the app if they previously registered a secondary authentication method, such as a mobile phone number or personal email, in their Microsoft security profile. If they click "Sign in another way" and no options appear, the system strictly enforces the app, and they must contact their IT administrator to clear the old device binding.
How long does the Microsoft Data Protection team take to unlock a sole administrator?
Recovering a sole administrator account through the Data Protection team is a manual security process that typically takes between 24 to 72 hours. Because the team must rigorously verify your identity and domain ownership to prevent social engineering attacks, this timeline cannot be bypassed or expedited through standard support channels.
Why does the login screen still ask for an app code after an admin revokes my sessions?
If an admin clicks "Revoke MFA sessions" but forgets to click "Require re-register MFA," the system terminates your current logins but still expects a code from the old, disconnected app. The administrator must specifically trigger the "Require re-register MFA" command in Entra ID to force the system to generate a new setup QR code for you.
What is a break-glass account and how does it prevent MFA lockouts?
A break-glass account is a dedicated, highly monitored global administrator profile that operates entirely independently of your standard single sign-on or primary MFA devices. It is configured with a complex, uniquely generated password and hardware token (or exceptionally long alternate verification code) stored securely offline, ensuring that if all primary admins lose their devices, you still have backdoor administrative access to reset the tenant.




