Appearance
How to Understand MFA and Prevent Account Lockouts
Applies to: Microsoft 365, Microsoft Authenticator
Article Type: Informational
Last Updated: 2026-05-18
Summary
Multi-factor authentication (MFA) protects your account, but it can also lock you out if your only verification method becomes unavailable. This article explains what MFA is, why lockouts happen, how to set up multiple backup methods so you are never locked out, and what to do if you already are.
Prerequisites
- Microsoft 365 account with MFA enabled by your organization.
- Access to at least one working MFA method (Authenticator app, phone, or email) to add backup methods.
Instructions
1. What Is MFA and Why Does Your Organization Require It?
MFA (multi-factor authentication) requires two forms of proof when you sign in — not only your password.
Think of it like a building with two locks:
- Lock 1 — Something you know: Your password.
- Lock 2 — Something you have: Your phone (via the Authenticator app, a text message code, or a phone call).
Even if someone steals or guesses your password, they cannot access your account without your phone. This is why your organization requires MFA — it stops over 99% of account-compromise attacks.
2. How MFA Works When You Sign In
Here is what happens each time you sign in to Microsoft 365:
- You enter your email address and password on the sign-in page.
- Microsoft checks your password. If correct, it does not let you in yet — it sends a verification request to your registered MFA method.
- If you use the Authenticator app: A push notification appears on your phone with a two-digit number. You match the number in the app and tap Approve.
- If you use SMS: A text message arrives with a six-digit code. You type the code into the sign-in page.
- If you use a phone call: Your phone rings and you press # to confirm.
- Once you approve, you are signed in.
Note: On trusted devices (your work computer, for example), you may not be prompted every time. Your organization sets how frequently MFA is required.
3. The #1 Cause of MFA Lockouts
You replace, reset, or lose your phone — and the Authenticator app disappears with it.
Here is what typically happens:
- You get a new phone (upgrade, replacement, or factory reset).
- The Microsoft Authenticator app was on your old phone. It does not transfer automatically to your new phone — not through iCloud backup, Google backup, or SIM swap.
- You try to sign in to Microsoft 365 on your computer.
- Microsoft asks you to approve a notification on the Authenticator app.
- The app no longer exists. You have no way to approve.
- You are locked out.
This is the single most common MFA support ticket. It is entirely preventable.
4. Set Up Multiple Backup Methods (Do This Now) ⭐
The solution is to register at least two MFA methods so that if one becomes unavailable, you can fall back to another.
- Open a browser and go to https://mysignins.microsoft.com/security-info.
- Sign in and approve the MFA prompt.
- Review your current methods. You will see at least one entry (e.g., Microsoft Authenticator).
- Click + Add sign-in method.
- Add the following backup methods:
| Method | How to Add | Why It Helps |
|---|---|---|
| Phone (SMS) | Select Phone, enter your mobile number, choose Text me a code | Works on any phone with your number — even if Authenticator is gone |
| Phone (Call) | Select Phone, enter your number, choose Call me | Works even without a smartphone |
| Alternate email | Select Email, enter a personal email address | Useful if you lose your phone entirely |
| Authenticator on a second device | Select Authenticator app, scan QR with a tablet or spare phone | Full Authenticator functionality on a backup device |
- After adding each method, verify it works by following the confirmation prompts.
- Return to the Security info page and confirm at least two methods are listed.
Verification: Your Security info page shows two or more active sign-in methods. If you covered your phone's camera and pretended it was gone, you could still sign in using SMS or email.
5. Before You Get a New Phone — Checklist
Run through this checklist before you swap, reset, or trade in your phone:
- [ ] Test the backup method — sign out and sign back in using SMS or email to confirm it works.
- [ ] If SMS is your backup, confirm your phone number will carry over to the new device (same SIM or number transfer).
- [ ] After setting up your new phone, install Microsoft Authenticator and re-register it. See How to Transfer MFA to a New Phone for the full walkthrough.
- [ ] Remove your old phone from the Security info page after the new one is working.
6. What to Do If You Are Already Locked Out
If you cannot approve MFA and have no backup methods:
- Check for alternative methods first. On the sign-in screen, look for "I can't use my Microsoft Authenticator app right now" or "Use a different verification option". If SMS or email is registered, you may be able to use it.
- If no alternatives exist, contact your IT helpdesk. Provide:
- Your full name and email address.
- Your employee ID (if applicable).
- Your manager's name (for identity verification).
- IT will perform a temporary MFA reset. This clears your registered methods and gives you a window to sign in and re-register.
- Once you regain access, immediately set up multiple methods (Method 4 above) so this does not happen again.
Note: IT may issue a Temporary Access Pass (TAP) — a one-time code that lets you sign in without MFA for a limited time. Use it promptly.
7. Best Practices for MFA
Keep your account secure and accessible.
- Maintain at least two active MFA methods at all times. Check mysignins.microsoft.com/security-info quarterly.
- Keep the Authenticator app updated. Outdated versions may stop receiving push notifications.
- Never approve a prompt you did not initiate. If you receive an unexpected "Approve sign-in?" notification, tap Deny and report it to IT immediately — someone may be trying to access your account.
- Do not share verification codes. Microsoft and your IT team will never ask for your MFA code.
- Review your sign-in activity if anything looks suspicious. See How to Check Your Sign-In Activity in Microsoft 365.
Troubleshooting
DANGER
The most important thing you can do right now is go to mysignins.microsoft.com/security-info and confirm you have at least two sign-in methods registered. If you only have one, add a backup immediately — it takes less than two minutes and prevents the most common account lockout scenario.
| Symptom / Error | Potential Cause | Solution |
|---|---|---|
| Locked out after getting a new phone | Authenticator app was only MFA method | Contact IT for a temporary MFA reset. After regaining access, register SMS and re-install Authenticator (Method 4). |
| Authenticator not sending push notifications | App outdated or notifications blocked | Update the app. Check phone Settings > Notifications > Authenticator and ensure notifications are allowed. |
| Received an MFA prompt I did not request | Someone has your password and is attempting to sign in | Tap Deny. Change your password immediately. Report to IT. See How to Identify a Phishing Email. |
| SMS verification code never arrives | Phone number changed or poor reception | Try again in an area with better reception. If your number changed, contact IT to update your security info. |
| "Your sign-in was blocked" error | Too many failed MFA attempts or suspicious location | Wait 15 minutes and try again. If it persists, ask IT to confirm whether your account is locked and what triggered it — tell them roughly when you last tried to sign in. |
| Only see one MFA method on Security info page | No backup methods registered | Add at least one more method immediately (Method 4). Do not wait until you need it. |