← Back to Blog
Cybersecurity

Lost Phone With Microsoft Authenticator? Get Back In

3 October 2026 · By Ethan Fernandes

Lost Phone With Microsoft Authenticator? Get Back In

Lost or replaced your phone and now Microsoft 365 says "Approve sign in request" or "More information required"? Here's how to get back in and stay safe.

Your phone is lost, broken or traded in, and Microsoft 365 is still asking you to "Approve sign in request" in the Authenticator app, or to "Enter code" sent to a number you no longer have. On a new phone, the Authenticator app opens with no work account in it, or the account shows but says "Action required". Either way, you're locked out of email, Teams and files.

The good news: this is fixable, usually within minutes, but it needs the right person to do the right step. Here's what you can do, what your admin needs to do, and how to make sure it never stops work again.

Quick answer

First try any other sign-in method you've registered, via "Sign in another way" on the prompt. If you have none, contact your Microsoft 365 admin: they can verify your identity, issue a Temporary Access Pass or require you to re-register MFA, and remove the old phone. Then set up at least two methods so it doesn't happen again.

Why This Happens

Multi-factor authentication (MFA) is working as intended. Your account trusts a specific device or phone number, and Microsoft can't tell the difference between you on a new phone and an attacker on theirs. Moving to a new phone doesn't automatically move a work account in Authenticator, and even when an Authenticator backup restores the account, work accounts often need extra verification before they work again.

If the phone was lost or stolen rather than replaced, tell your admin straight away, even if you can still sign in another way. They should remove the lost device from your account and, if it was a company phone, wipe or lock it through Intune.

Step 1: Try Another Sign-In Method

On the sign-in screen, look for "Sign in another way" or "I can't use my Microsoft Authenticator app right now". If you previously added a second method, such as a text to another phone, an office phone, a security key or Authenticator on a tablet, choose it.

Once you're in, go to https://mysignins.microsoft.com/security-info (or aka.ms/mysecurityinfo) and:

  1. Delete the old phone's Authenticator entry and any phone number you no longer have.
  2. Choose Add sign-in method and set up Authenticator on your new phone by scanning the QR code shown.
  3. Set your preferred method to the new Authenticator.

Step 2: Try Restoring From an Authenticator Backup

If you replaced your phone and turned on backup in the old Authenticator app, you may be able to restore:

  • iPhone: backup uses iCloud. Install Authenticator, sign in with the same Apple account and choose Begin recovery.
  • Android: backup requires a personal Microsoft account. Install Authenticator and choose Begin recovery with that account.

Restored work accounts frequently show a message that further verification is needed. Tap the account and follow the prompt. If it asks you to scan a QR code, you'll need to sign in to security info using another method, or ask your admin for help.

Step 3: Contact Your Admin

If you can't sign in another way, you need your Microsoft 365 administrator. Expect them to verify who you are before they help, ideally on a video call or in person. That's good security: helpdesk impersonation is a well-known way attackers bypass MFA.

For Your Microsoft 365 Admin

Verify the user's identity first. Then, in the Entra admin centre, open Users, select the user and go to Authentication methods. You have three main options:

  1. Remove the old methods. Delete the lost phone's Authenticator registration and any old phone numbers listed.
  2. Require re-register multifactor authentication. This option on the same page makes the user set up MFA again at their next sign-in. It works best when they can still sign in with their password from a trusted location.
  3. Issue a Temporary Access Pass (TAP). A TAP is a time-limited passcode that lets the user sign in and register new methods without the old phone. First make sure Temporary Access Pass is enabled in the Authentication methods policies (look under Protection or Authentication methods). Then, on the user's Authentication methods page, choose Add authentication method and select Temporary Access Pass. Set a short lifetime and one-time use, and give the code to the user over a separate, verified channel.

With the TAP, the user goes to aka.ms/mysecurityinfo, signs in, and registers Authenticator on the new phone plus a backup method.

If the phone may be in someone else's hands, also choose Revoke sessions on the user's page in Entra, reset the password if there's any doubt, and retire or wipe the device in the Intune admin centre if it was enrolled.

If the person locked out is your only admin, you need a break-glass (emergency access) account. Microsoft recommends at least two cloud-only emergency admin accounts protected by strong methods, such as FIDO2 security keys, stored securely. Without one, you're relying on Microsoft support to prove tenant ownership, which is slow.

How to Stop It Happening Again

Every user should have at least two independent sign-in methods registered. Good combinations are:

  • Microsoft Authenticator on their phone, plus a FIDO2 security key or passkey kept on their keyring.
  • Authenticator plus Windows Hello for Business on their work laptop.
  • Authenticator plus a phone number they'll keep, such as a direct office line. Text and voice are weaker than the other options, so treat them as a fallback rather than a main method.

Turn on backup in the Authenticator app, and add a new phone before wiping the old one. For the business, keep an admin-led recovery process in writing: who can verify identity, how TAPs are issued, and what happens out of hours. Our guide to password managers covers storing recovery details safely.

When to Call in Help

If nobody in your business can manage MFA, or your only admin is the one locked out, we can help you regain access and set up recovery properly. Our cybersecurity service covers MFA design, break-glass accounts and Conditional Access, and our managed IT service handles lost devices and lockouts day to day. Contact us if you're stuck now.

Common questions

Choose Sign in another way and use any backup method you registered. If you have none, your Microsoft 365 admin can issue a Temporary Access Pass or require you to re-register MFA after verifying your identity.

Before wiping the old phone, sign in to aka.ms/mysecurityinfo, add Authenticator on the new phone with the QR code, then remove the old entry. Authenticator's cloud backup can help, but work accounts often need re-verifying afterwards.

It's a time-limited passcode an admin issues in Entra ID so a user can sign in and register new MFA methods without their old device. It should be short-lived, one-time use where possible, and given out only after verifying the user's identity.

Yes. An admin can delete your old methods or use Require re-register multifactor authentication in the Entra admin centre, so you set up MFA again at your next sign-in.

Want to talk about this?

Book a free 15-minute call and we'll discuss how this applies to your business.

Get IT tips in your inbox

Practical advice for small businesses. No spam.