Appearance
Summary
Multi-factor authentication (MFA) protects your account, but it can also lock you out if your only verification method becomes unavailable. This article explains what MFA is, why lockouts happen, how to set up multiple backup methods so you are never locked out, and what to do if you already are.
Before You Start
- Microsoft 365 account with MFA enabled by your organization.
- Access to at least one working MFA method (Authenticator app, phone, or email) to add backup methods.
Instructions
1. What Is MFA and Why Does Your Organization Require It?
MFA (multi-factor authentication) requires two forms of proof when you sign in — not only your password.
Think of it like a building with two locks:
- Lock 1 — Something you know: Your password.
- Lock 2 — Something you have: Your phone (via the Authenticator app, a text message code, or a phone call).
Even if someone steals or guesses your password, they cannot access your account without your phone. This is why your organization requires MFA — it stops over 99% of account-compromise attacks.
2. How MFA Works When You Sign In
Here is what happens each time you sign in to Microsoft 365:
- You enter your email address and password on the sign-in page.
- Microsoft checks your password. If correct, it does not let you in yet — it sends a verification request to your registered MFA method.
- If you use the Authenticator app: A push notification appears on your phone with a two-digit number. You match the number in the app and tap Approve.
- If you use SMS: A text message arrives with a six-digit code. You type the code into the sign-in page.
- If you use a phone call: Your phone rings and you press # to confirm.
- Once you approve, you are signed in.
Note: On trusted devices (your work computer, for example), you may not be prompted every time. Your organization sets how frequently MFA is required.
3. The #1 Cause of MFA Lockouts
You replace, reset, or lose your phone — and the Authenticator app disappears with it.
Here is what typically happens:
- You get a new phone (upgrade, replacement, or factory reset).
- The Microsoft Authenticator app was on your old phone. It does not transfer automatically to your new phone — not through iCloud backup, Google backup, or SIM swap.
- You try to sign in to Microsoft 365 on your computer.
- Microsoft asks you to approve a notification on the Authenticator app.
- The app no longer exists. You have no way to approve.
- You are locked out.
This is the single most common MFA support ticket. It is entirely preventable.
4. Set Up Multiple Backup Methods (Do This Now) ⭐
The solution is to register at least two MFA methods so that if one becomes unavailable, you can fall back to another.
- Open a browser and go to https://mysignins.microsoft.com/security-info.
- Sign in and approve the MFA prompt.
- Review your current methods. You will see at least one entry (e.g., Microsoft Authenticator).
- Click + Add sign-in method.
- Add the following backup methods:
| Method | How to Add | Why It Helps |
|---|---|---|
| Phone (SMS) | Select Phone, enter your mobile number, choose Text me a code | Works on any phone with your number — even if Authenticator is gone. Microsoft-provided SMS retires February 1, 2027 — see the note below |
| Phone (Call) | Select Phone, enter your number, choose Call me | Works even without a smartphone. Same February 1, 2027 retirement as SMS |
| Alternate email | Select Email, enter a personal email address | Useful if you lose your phone entirely |
| Authenticator on a second device | Select Authenticator app, scan QR with a tablet or spare phone | Full Authenticator functionality on a backup device |
- After adding each method, verify it works by following the confirmation prompts.
- Return to the Security info page and confirm at least two methods are listed.
Verification: Your Security info page shows two or more active sign-in methods. If you covered your phone's camera and pretended it was gone, you could still sign in using SMS or email.
SMS and phone calls have an announced end date. Microsoft is making passkeys the default sign-in experience for work accounts. From September 1, 2026, passkeys are enabled automatically for anyone currently set up for SMS or voice, and the next time those users sign in and complete MFA they are prompted to register one — a prompt you can snooze, by default as often as you like. From February 1, 2027, organizations that have not arranged their own telecom provider through the Microsoft Security Store can no longer use SMS or voice for MFA; organizations that do arrange one keep both. Register SMS today — it is still the fallback that works when your phone is new and the Authenticator app is gone — and pair it with a method that does not depend on a text message: the Authenticator app on a tablet or spare phone, or a passkey.
5. Before You Get a New Phone — Checklist
Run through this checklist before you swap, reset, or trade in your phone:
- [ ] Test the backup method — sign out and sign back in using SMS or email to confirm it works.
- [ ] If SMS is your backup, confirm your phone number will carry over to the new device (same SIM or number transfer).
- [ ] After setting up your new phone, install Microsoft Authenticator and re-register it. See How to Transfer MFA to a New Phone for the full walkthrough.
- [ ] Remove your old phone from the Security info page after the new one is working.
6. What to Do If You Are Already Locked Out
If you cannot approve MFA and have no backup methods:
- Check for alternative methods first. On the sign-in screen, look for "I can't use my Microsoft Authenticator app right now" or "Use a different verification option". If SMS or email is registered, you may be able to use it.
- If no alternatives exist, contact your IT helpdesk. Provide:
- Your full name and email address.
- Your employee ID (if applicable).
- Your manager's name (for identity verification).
- IT will perform a temporary MFA reset. This clears your registered methods and gives you a window to sign in and re-register.
- Once you regain access, immediately set up multiple methods (Method 4 above) so this does not happen again.
Note: IT may issue a Temporary Access Pass (TAP) — a one-time code that lets you sign in without MFA for a limited time. Use it promptly.
7. Best Practices for MFA
Keep your account secure and accessible.
- Maintain at least two active MFA methods at all times. Check mysignins.microsoft.com/security-info quarterly.
- Keep the Authenticator app updated. Outdated versions may stop receiving push notifications.
- Never approve a prompt you did not initiate. If you receive an unexpected "Approve sign-in?" notification, tap Deny and report it to IT immediately — someone may be trying to access your account.
- Do not share verification codes. Microsoft and your IT team will never ask for your MFA code.
- Review your sign-in activity if anything looks suspicious. See How to Check Your Sign-In Activity in Microsoft 365.
- Add a passkey when your organization offers one. A passkey signs you in with your fingerprint, face, or PIN and replaces both the password and the MFA prompt — Understanding Passkeys explains how they work and why sign-ins are moving that way, and How to Use Passkeys Instead of Passwords in Microsoft 365 walks through registering one on your work account. A passkey is the step after MFA rather than a replacement for it: there is no password left to steal, so there is no prompt for an attacker to trigger and nothing for you to approve by mistake. Keep your backup methods registered either way — they are how you get back in if the device holding the passkey is lost.
Troubleshooting
DANGER
The most important thing you can do right now is go to mysignins.microsoft.com/security-info and confirm you have at least two sign-in methods registered. If you only have one, add a backup immediately — it takes less than two minutes and prevents the most common account lockout scenario.
| Symptom / Error | Potential Cause | Solution |
|---|---|---|
| Locked out after getting a new phone | Authenticator app was only MFA method | Contact IT for a temporary MFA reset. After regaining access, register SMS and re-install Authenticator (Method 4). |
| Authenticator not sending push notifications | App outdated or notifications blocked | Update the app. Check phone Settings > Notifications > Authenticator and ensure notifications are allowed. |
| Received an MFA prompt I did not request | Someone has your password and is attempting to sign in | Tap Deny. Change your password immediately. Report to IT. See How to Identify a Phishing Email. |
| SMS verification code never arrives | Phone number changed or poor reception | Try again in an area with better reception. If your number changed, contact IT to update your security info. |
| "Your sign-in was blocked" error | Too many failed MFA attempts or suspicious location | Wait 15 minutes and try again. If it persists, ask IT to confirm whether your account is locked and what triggered it — tell them roughly when you last tried to sign in. |
| Only see one MFA method on Security info page | No backup methods registered | Add at least one more method immediately (Method 4). Do not wait until you need it. |
Related Articles
- How to Use the Microsoft Authenticator App
- How to Transfer MFA to a New Phone (Microsoft 365)
- How to Set Up Self-Service Password Reset (SSPR)
- How to Use Passkeys Instead of Passwords in Microsoft 365
- How to Check Your Sign-In Activity in Microsoft 365
- How to Identify a Phishing Email
- Understanding Microsoft 365 Account Security — What Protects You and Why