Skip to content

How to Understand MFA and Prevent Account Lockouts

Applies toMicrosoft 365Microsoft Authenticator
5 min fix Updated 21 Aug 2026
Quick Answer

MFA (multi-factor authentication) requires a second proof of identity — usually a phone notification or code — after your password. Register at least two MFA methods (like the Microsoft Authenticator app and a phone number) so you are not locked out if one becomes unavailable.

Checked against Microsoft Learn - end of support and retirement, Microsoft 365 Roadmap and between 5 Aug 2026 and 12 Sep 2026. Nothing published in that period has been linked to this guide.

Last updated:

Frequently asked questions

Why do I get locked out if I break my phone?
MFA relies on proving you possess a physical device (your phone). If the phone breaks and you only set up the Authenticator app, the system has no other way to verify your identity.
How many backup methods should I have?
You should always have at least two. The Authenticator app is the best primary method, and a passkey is where sign-in is heading — Microsoft is making passkeys the default experience for work accounts. Add a personal email address or a phone number for SMS codes as a fallback as well, bearing in mind that Microsoft-provided SMS and voice codes retire on February 1, 2027 for organizations that have not arranged their own telecom provider.