A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
The account is in an MFA deadlock: the browser requires Microsoft Authenticator, and Authenticator requires reconfiguration via a QR code that is only shown after sign-in.
Resolution depends on whether this is a work/school (Entra ID) developer tenant and whether there is another admin.
- If there is another administrator on the tenant
- Ask the other admin to reset MFA for the affected account in Microsoft Entra:
- Go to Microsoft Entra admin center (entra.microsoft.com).
- Navigate to Users → All users and select the locked-out account.
- Open Authentication methods.
- Choose Require re-register multifactor authentication.
- After this, sign in again; the portal will prompt to set up Microsoft Authenticator from scratch with a new QR code.
- Ask the other admin to reset MFA for the affected account in Microsoft Entra:
- If there is no other administrator (only one global admin)
- This is the same scenario described in the referenced Q&A threads. In that case, only Microsoft’s Data Protection team can verify identity and reset MFA.
- Call Microsoft Support using the regional Customer service phone numbers - Microsoft Support entry and request a ticket with the Data Protection team for an admin MFA reset on the tenant. When navigating the IVR/agent, clearly state:
- The product is Office 365 for business / Microsoft 365.
- It is a company/work account.
- The caller is the only administrator and is locked out due to Microsoft Authenticator.
- Follow their identity verification steps; once they reset MFA, sign in again and reconfigure Authenticator with the new QR code.
- Alternative path if phone support cannot be reached
- Create a temporary trial Microsoft 365 tenant (separate from the locked one) as described in the Q&A context.
- From that new tenant’s admin center, open a support ticket explicitly stating that access is needed to a different, existing tenant where the caller is the only admin and is locked out by MFA.
- Ask support to escalate to the Data Protection team for an admin MFA reset on the original developer tenant.
Until MFA is reset by another admin or by Microsoft’s Data Protection process, the loop between Authenticator and the browser cannot be broken.
References: