Infiinte Loop MFA

Kevin Doan 5 Reputation points
2024-12-18T23:15:57.1566667+00:00

I just got a new iPhone, and my authenticator app does not have my previous accounts stored. I am receiving a request to sign in with the Auth App, but when I click "I can't use my Microsoft Authenticator app right now," it just keeps looping back to options that require the Authenticator app.

Screenshot 2024-12-18 at 3.10.35 PM

Screenshot 2024-12-18 at 3.12.03 PM

Both these options loop to the Authenticator app.
I have been doing this for over 2 weeks now, and the IT call number doesn't actually go to a person.

Any help is actually progress.

Microsoft Authenticator
Microsoft Authenticator
A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation.
7,510 questions
Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
851 questions
Microsoft Entra Internet Access
Microsoft Entra Internet Access
A Microsoft Entra service that provides an identity-centric Secure Web Gateway that protects access to internet, software as a service (SaaS), and Microsoft 365 apps and resources.
28 questions
0 comments No comments
{count} vote

1 answer

Sort by: Most helpful
  1. Sandeep G-MSFT 20,266 Reputation points Microsoft Employee
    2024-12-19T04:43:22.2933333+00:00

    @Kevin Doan

    Thank you for posting this in Microsoft Q&A.

    As I understand you are unable to login to Azure services as you are getting MFA prompts which is in infinite loop.

    You have got a new phone, and you do not have authenticator app installed in it.

    In this situation you have 2 ways to solve this issue.

    • If you have another Global admin of your tenant
    • If you are the only Global admin of your tenant

    If you have another Global admin of your tenant, you can ask them to make change in Entra ID for your account so that you can re-register for MFA in authenticator app. To perform this, you can ask another Global admin to follow below steps,

    • Admin has to login to Azure portal and access Azure active directory.
    • Once done they have to go to users blade on the left.
    • Click on the user account which has been locked out.
    • Click on Authentication methods and click on “Require re-register multifactor authentication”.
    • Now when you try to login to Azure services it will prompt you to register for MFA again.

     

    If you are the only global admin on the account and are blocked entirely, you can reach out to our support team. You can look into below article to get support numbers depending on your country.

    https://support.microsoft.com/en-us/topic/global-customer-service-phone-numbers-c0389ade-5640-e588-8b0e-28de8afeb3f2

    or creating a ticket through a different account:  https://learn.microsoft.com/en-us/microsoft-365/admin/get-help-support?view=o365-worldwide#phone-support

    Create a ticket with Microsoft support team. Give them the tenant ID which is locked out in your description. Tell them that no admin account has access anymore and your partners also have no access anymore.

    Once you create a ticket with support team you will have to work with our data protection team. You will have to first prove your identity against your tenant for security purpose. Post that this team will help you with help you in getting access to your tenant or unlock your account depending on your scenario.

    Also, for the future, you can create an emergency access account (break glass) in Azure AD. This account will help prevent being accidentally locked out of your Azure Active Directory (Azure AD) organization because you can't sign in for any reason.

    https://docs.microsoft.com/en-us/azure/active-directory/roles/security-emergency-access

     

    Let me know if you have any further questions.

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.