Microsoft Authenticator not working? 6 safe steps for your work account

By Črt Kranjc · Published · Updated

Notification not arriving, code rejected, or changed phones? Six safe steps for a work account, a second administrator and recovering the sole administrator.

If the notification doesn't arrive, first check your internet connection, notification permissions, Do Not Disturb mode, the app update status, and automatic date and time. If you've changed phones, use another already registered sign in method or contact your administrator. If the only Global Administrator is locked out, proceed through official Microsoft support.

Decision tree

First work out which case applies to you.

1. The approval notification doesn't arrive

For a push notification, first check the basic conditions on your phone:

  • the phone has a working internet connection,
  • notifications for Microsoft Authenticator are allowed,
  • Do Not Disturb or focus mode isn't hiding the notification,
  • Microsoft Authenticator and the operating system are up to date,
  • date and time are set automatically.

Then, if available, choose to resend the notification on the sign in screen. Microsoft also has official troubleshooting instructions for the Authenticator app .

2. The six digit code doesn't work

Check that you're looking at the correct work account and entering the current code. Codes change regularly, so wait for a new one if the previous one was about to expire. The correct time on your phone matters too; use the automatic setting for date, time and time zone.

If sign in still fails, note down the error code shown, the time, and the app you're signing into. This information helps the administrator distinguish an MFA method issue from an access policy or account block.

3. Use another already registered sign in method

On the Microsoft sign in screen, look for an option for another sign in method. Use only a method that was already registered on the account and that your organisation allows. If there's no other option, the next step for a work account is a designated administrator, not creating workarounds or a new personal account.

4. You've changed phones

If the old phone is still available, complete the transfer first and test signing in on the new phone before deleting the old device. For work accounts, restoring a backup carries over the account information, but full functionality usually requires signing in again or re registering.

Microsoft's instructions for transferring Authenticator to a new phone stress that the process should be completed before deleting or handing in the old device.

5. Another administrator requires MFA re registration

If the organisation has another working administrator account, they can, after verifying the user's identity, review their sign in methods and require MFA re registration. This is an administrative action: the Require re register MFA option removes existing phone numbers, Authenticator and software OATH methods, so it shouldn't be used without a prepared path for re registration.

The process should be carried out by an authorised administrator or IT support. In certain environments a temporary access pass may be appropriate, but its use depends on the organisation's policies and settings.

Official instructions for managing user sign in methods .

6. The only Global Administrator is locked out

If there's no other administrator or emergency access, self service re registration may not be possible. In that case, gather details about the organisation, domain, subscription, tenant ID, error code and time of the failed sign in, and open a case with Microsoft support. Microsoft must verify identity and ownership of the environment before recovery.

An IT provider can't bypass Microsoft's verification in this case. They can, however, help prepare the information, open the correct support path and track the official recovery process.

How to prevent the next access outage

  • keep regular user and administrator accounts separate,
  • make sure there's more than one independent administrative path,
  • document phone changes and MFA re registration,
  • regularly review sign in methods and administrator roles,
  • prepare and test emergency access accounts.

Microsoft currently recommends at least two separate, cloud only accounts for emergency access, with a strong sign in method that doesn't depend on the same phone as your regular administrator accounts. Their functioning should be checked regularly.

Microsoft's recommendations for emergency access accounts .

When to bring in IT support

Bring in help immediately if an administrator account is affected, if you don't know who has administrator access, or if sign in still fails after the basic checks. For a regular user with another working administrator, the solution is often clear; for the sole administrator, it's important to start the official recovery path straight away.

More on setting up access, licences and security is on the Microsoft 365 support for small companies page.

Frequently asked questions

Why doesn't the Microsoft Authenticator notification arrive?

Check your internet connection, that notifications for the app are allowed, that Do Not Disturb isn't hiding it, that the app and operating system are up to date, and that date and time are set automatically.

What should I do if I've changed phones and Authenticator no longer works?

If your old phone still works, complete the transfer and test sign in on the new phone before deleting the old device. For work accounts, full functionality usually requires signing in again or re registering.

What if the only Global Administrator account is locked out?

Gather the organisation's details, domain, subscription, tenant ID, error code and time of the failed sign in, then open a case with official Microsoft support, since identity and ownership must be verified before recovery.

How do I prevent this from happening again?

Keep user and administrator accounts separate, set up more than one independent administrative path, document phone changes, regularly review sign in methods and administrator roles, and prepare tested emergency access accounts.