Guides / Lost phone or new phone: Microsoft Authenticator recovery
Last reviewed 5 Oct 2026
Lost phone or new phone: Microsoft Authenticator recovery
Lost the phone that had Microsoft Authenticator, or moved to a new handset? What users can do and what admins must reset safely.
The phone is in a taxi, in the washing machine, or traded in at the shop without Authenticator migrated. The user cannot approve the sign-in prompt. This feels like being locked out of work forever. It is a standard identity recovery job — provided your tenant prepared a backup method, and provided nobody "helps" by weakening MFA for the whole company.
Is Microsoft sign-in down?
No. A single user without their MFA device is not an Entra ID incident. Check status only if many people fail MFA at once. For Okta-managed environments the same story applies with Okta Verify — see the Okta push guide for app-side fixes, then treat lost-device recovery like this page.
User options before you call the helpdesk
- Another registered method. On the sign-in page choose "Other ways to sign in" / "Sign in a different way". SMS, voice, a hardware key, or a second Authenticator may already be registered.
- Backup codes / Temporary Access Pass. If your admin gave you a TAP or printable temporary codes, use them now. They expire; that is intentional.
- iCloud / Authenticator backup. Microsoft Authenticator on iOS can use iCloud backup when the account encryption is set up beforehand. On Android, cloud backup / account recovery features vary by version — they only work if they were enabled before the phone died. Hoping after the fact does not recreate the secrets.
- Do not factory-reset the only remaining PC session while you still have a signed-in browser somewhere. That session may be how an admin verifies you.
New phone, old phone still in hand
This is the easy path. On the old phone open Authenticator, use the transfer / backup features Microsoft documents for your platform, or add the work account on the new phone by signing in and scanning new QR codes while the old phone can still approve. Remove the old device from mysignins.microsoft.com/security-info once the new one works. Never leave a traded-in phone enrolled.
Admin recovery (Entra ID)
- Verify the human. Lost-phone tickets are a favourite of social engineers. Use your identity-proofing process (manager callback, HR photo ID, known device) before you touch MFA.
- Authentication methods. In the Entra admin centre, open the user → Authentication methods. Delete the dead Authenticator registration. Add a Temporary Access Pass with a short lifetime and require MFA re-registration, or register a phone number you have verified out of band.
- Require re-register MFA via the per-user flag or Conditional Access / authentication strength policies that demand a fresh method at next sign-in.
- Revoke sessions. After a lost phone — especially if it was unlocked — revoke refresh tokens / sign the user out everywhere from Entra.
- SSPR interaction. If the user also forgot the password, fix MFA methods first or combine with a helpdesk password reset. SSPR cannot succeed without a reachable registered method.
Okta and other IdPs
If Okta owns MFA, an Okta admin resets factors on the user profile (Reset Authenticators) and the user re-enrols. Do not reset Entra methods for an app that never sees Entra MFA. Know which directory owns the prompt before you tear things out.
Prevention worth doing tomorrow
Require at least two MFA methods for staff who travel. Prefer TAP playbooks over SMS-only recovery. Tell people to enrol the new phone before wiping the old one. Keep break-glass admin accounts offline and monitored.
When to escalate
Escalate to Microsoft when admin tools refuse to delete a dead method, TAP cannot be created despite correct licensing and roles, or many users lose Authenticator registrations after a tenant change. For one lost handset with a clear proofing path, it is a standard service-desk job — not a cloud outage.
Related status pages
Related guides
- Microsoft Authenticator not getting notifications: fixes
- Entra ID / Azure AD password reset email or code not arriving
- Okta Verify push not arriving or stuck in an MFA loop
FAQ
- I lost my phone with Microsoft Authenticator — how do I sign in?
- Try Other ways to sign in for SMS, another device or a hardware key. If nothing else is registered, contact your IT admin for a Temporary Access Pass or an authentication-methods reset after they verify your identity.
- Can I restore Authenticator on a new phone from backup?
- Only if Authenticator backup was enabled before the old phone was lost. Otherwise an admin must clear the old registration and you enrol fresh on the new device.
- Should IT turn off MFA until I get a new phone?
- No. Use a short-lived Temporary Access Pass or a verified alternate method. Disabling MFA for the account or the tenant creates a larger incident than a lost handset.
- Is a lost Authenticator phone an Entra outage?
- No. It is account recovery. Check Entra status only if many users fail MFA at the same time.