Guides / Microsoft 365 sign-in loop or 'More information required'
Last reviewed 5 Oct 2026
Microsoft 365 sign-in loop or 'More information required'
Stuck bouncing between sign-in pages, or told 'More information required'? What it means, how users break the loop, and what admins check in Entra.
Two tickets that look alike. In the first, the user signs in and the page bounces back to the sign-in screen, again and again. In the second, Microsoft says More information required and asks them to set up security info they do not understand. Neither usually means Microsoft is down.
"More information required" is not an error
It means the tenant now requires the user to register a sign-in method, usually the Microsoft Authenticator app or a phone number, before they can carry on. It appears after an admin turns on security defaults, a Conditional Access policy that requires MFA, or a registration campaign. The user should click Next and finish the setup. If they cannot (no smartphone, wrong country code, already set up on an old phone), that is an admin task, below. Users can review their methods any time at mysignins.microsoft.com/security-info.
Breaking a sign-in loop: user steps
- Private window. Open an InPrivate or Incognito window and go to office.com. If that works, the normal profile has a bad cookie or another account signed in.
- One account at a time. Personal Microsoft accounts and work accounts with the same email address cause loops. In the account picker, choose "Work or school account" when asked.
- Clear cookies for Microsoft sign-in only (login.microsoftonline.com and login.live.com), rather than the whole browser.
- Check the clock. A PC or phone with the wrong time or time zone can fail token validation. Set time to automatic.
- Turn off extensions that block cookies, scripts or trackers for the sign-in pages.
- Try another device. If the phone signs in and the PC loops, it is the PC. If both loop, it is the account or a policy.
Admin checks in Entra
Open the user's sign-in logs in the Microsoft Entra admin centre. The failure reason and code are the whole story. The common ones:
- AADSTS50126 — wrong username or password.
- AADSTS50053 — account locked, usually by smart lockout after repeated bad passwords (often an old phone or a mapped drive with a stale password).
- AADSTS50057 — account disabled.
- AADSTS50055 — password expired.
- AADSTS50076 — MFA required for this sign-in (new location, policy change).
- AADSTS50079 — the user must register for MFA. This is "More information required".
- AADSTS53003 — blocked by Conditional Access. The log shows which policy.
- AADSTS50105 — the user is not assigned to the application.
- AADSTS50020 — the account is from another tenant or identity provider; often a guest using the wrong address.
Then the fixes that actually help:
- Lost phone or new phone: on the user's Authentication methods page, use Require re-register multifactor authentication, or issue a Temporary Access Pass if your tenant allows it, so they can register the new device.
- Conditional Access: run the What If tool for the user, app and device. Loops often come from a policy that requires a compliant or joined device the user does not have.
- Federated domains: if sign-in redirects to Okta, ADFS or another provider, the loop may be there, not in Entra.
When to escalate
If many users across different devices fail at the same time, the sign-in logs show service-side errors rather than policy decisions, and the Entra ID or Microsoft 365 status shows an incident, it is Microsoft: tell people, and stop resetting passwords. If one user loops and the logs show a policy blocking them, the fix is the policy or the device, and it belongs to whoever owns Conditional Access. Keep a tested break-glass admin account excluded from MFA policies, so a policy mistake does not lock everyone out.
Related status pages
Related guides
- Microsoft Authenticator not getting notifications: fixes
- Outlook keeps asking for a password: how to stop the prompts
- Okta SSO not working: outage, MFA, or account lockout?
FAQ
- What does 'More information required' mean when signing in to Microsoft 365?
- Your organisation requires you to register a security method, usually the Microsoft Authenticator app or a phone number, before you can continue. Click Next and complete the setup. If you cannot, ask your IT admin to reset your MFA registration.
- Can I skip 'More information required'?
- Sometimes for a limited time, if your admin allows it; security defaults, for example, give a short grace period. After that, registration is required. Skipping is a tenant decision, not something users can change.
- Why does Microsoft 365 keep sending me back to the sign-in page?
- Usually a stale cookie, two accounts with the same email (personal and work), a wrong device clock, or a Conditional Access policy that rejects the device. Try a private window first, then another device.
- Where do admins see why a sign-in failed?
- In the Microsoft Entra admin centre, under the user's sign-in logs. Each failed sign-in shows an AADSTS code, the failure reason and any Conditional Access policy that applied.