Guides / Microsoft Authenticator not getting notifications: fixes
Last reviewed 5 Oct 2026
Microsoft Authenticator not getting notifications: fixes
Authenticator push not arriving for Microsoft 365 sign-in? Phone settings, the code fallback, a new phone, and the admin reset that gets people back in.
The sign-in screen shows a number and says "Approve sign-in request". The phone stays silent. The user waits, the request times out, and the ticket says "MFA is broken". Most of the time Microsoft's service is fine and the notification simply never reached the phone.
Get the user in right now
- Open Microsoft Authenticator directly. A pending request often appears inside the app even when the notification banner never showed.
- Use the code instead. On the sign-in screen choose I can't use my Microsoft Authenticator app right now or Sign in another way, then pick the verification code. The six-digit code in the app works without a push, as long as your tenant allows that method and the phone's clock is right.
- Any other registered method, such as a text message or phone call, if the tenant has those enabled.
Fix the phone
- Notifications allowed for Authenticator in the phone's settings, including lock-screen and banner notifications.
- Focus or Do Not Disturb modes silence it. So do work profiles on Android that are paused.
- Battery optimisation (Android) can stop the app receiving pushes in the background. Set Authenticator to unrestricted.
- Background App Refresh and Low Data Mode (iPhone) can delay or block notifications.
- Date and time on automatic. A drifting clock breaks the six-digit codes.
- Update the app. Old versions stop working with newer sign-in features.
- Connectivity. Pushes need mobile data or Wi-Fi. Guest Wi-Fi with a captive portal will quietly block them.
New phone, restored phone
Restoring Authenticator from a backup brings back personal accounts, but work or school accounts usually need to be signed in again or re-registered before push works. If the old phone is gone, the user cannot approve anything; that needs an admin. Users who still have another working method can add the new phone themselves at mysignins.microsoft.com/security-info.
Admin-level fixes (Entra)
- Check the sign-in log first. In the Microsoft Entra admin centre, the failed sign-in's authentication details show whether the push was sent, denied, or timed out. A "denied" result means the user, or someone, pressed deny.
- Require re-registration. On the user's Authentication methods page, Require re-register multifactor authentication makes them set up again at next sign-in. Delete the stale Authenticator entry for an old phone.
- Temporary Access Pass. If the policy is enabled, a time-limited pass lets the user sign in once and register the new phone without calling round for codes.
- Authentication methods policy. Confirm Microsoft Authenticator is enabled for this user's group and that the method the user is trying is allowed.
- Number matching is standard for Authenticator push. If users approve without seeing a number, they may be on an old app or a different MFA provider entirely.
Prompts nobody asked for
If a phone is buzzing with approval requests the user did not start, someone else has the password. Tell the user to deny them all. Reset the password, revoke the user's sessions in Entra, and check the sign-in logs for the location and IP that triggered them. That is a security incident, not a notification bug.
When to escalate
Escalate to Microsoft when many users across different phones and networks stop receiving pushes at the same time, the sign-in logs show the service failing to deliver, and the Entra ID or Microsoft 365 page shows an MFA or authentication incident. One user's phone is a desk fix.
Related status pages
Related guides
- Microsoft 365 sign-in loop or 'More information required'
- Okta Verify push not arriving or stuck in an MFA loop
- Outlook keeps asking for a password: how to stop the prompts
FAQ
- Why am I not getting Microsoft Authenticator notifications?
- Common causes are notifications disabled for the app, Focus or Do Not Disturb, Android battery optimisation, no data connection, or the account needing to be re-registered after a phone change. Open the app directly; a pending request often shows there.
- Can I sign in without the push notification?
- Usually. Choose 'Sign in another way' and use the six-digit code shown in Microsoft Authenticator, or another method your organisation allows, such as a text or call.
- I got a new phone. How do I move Microsoft Authenticator?
- Install Authenticator on the new phone, then add it at mysignins.microsoft.com/security-info while you can still sign in with the old phone or another method. If the old phone is gone, ask your IT admin to reset your MFA registration or issue a Temporary Access Pass.
- What should I do if I get approval requests I didn't start?
- Deny them and tell IT immediately. Someone likely has your password. Admins should reset the password and revoke active sessions.