Guide
How to reset multi-factor authentication for a Microsoft 365 user
A user replaces their phone, does not move the authenticator app across, and is locked out of everything at once. This is the single most common ticket a small business raises. The fix is to require MFA re-registration on that account, then have the user enrol the new device at next sign-in.
What you'll see
- "We couldn't sign you in" or a stalled approval prompt after entering the correct password
- The Authenticator app shows no account, or shows an account that no longer generates a working code
- The user can still sign in on an already-authenticated desktop session but not on a new device
The procedure
Step by step
Step 01
Confirm the identity of the requester
Before touching the account, verify the person is who they say they are — a callback to a known number, a confirmation from their manager, or an in-person check. MFA reset requests are a favourite pretext for attackers, and this step is the whole security value of the process.
Step 02
Open the user in Microsoft Entra ID
Sign in to the Microsoft Entra admin centre as a Global Administrator, Authentication Administrator or Privileged Authentication Administrator. Go to Identity, then Users, then All users, and open the affected account.
Step 03
Require re-registration of MFA
On the user's page, open Authentication methods and choose Require re-register multifactor authentication. This clears the existing registration without deleting the account, so the next sign-in prompts the user to enrol a fresh device.
Step 04
Revoke existing sessions
Still on the user's page, select Revoke sessions. This invalidates refresh tokens on devices that were already signed in, which matters if the old phone is lost, stolen or sold.
Step 05
Have the user enrol the new device
Ask the user to sign in at aka.ms/mfasetup on a trusted device and follow the enrolment prompts. Recommend they add two methods — the authenticator app plus a phone number or a second device — so the same lockout does not repeat.
Step 06
Confirm and record
Watch for a successful sign-in in the Entra sign-in logs, then record who requested the reset, who approved it, and when. If your organisation is working toward Cyber Essentials, this record is part of the evidence.
When to stop and escalate
Escalate if the account shows sign-ins from unexpected countries, if the user reports emails they did not send, or if inbox rules have appeared that forward mail externally. That is an account compromise, not a lost phone, and it needs containment first.
How AlwaysOnIT handles it
With AlwaysOnIT, the identity check and the reset both happen inside chat: the agent verifies the user against your identity provider, requests a short-lived scoped token, applies the re-registration requirement, revokes sessions and writes the whole sequence to your audit log.
Get started
Open a chat. The AI picks up before the second ring — every time.
No onboarding calls. No sales process. Connect your devices and start raising tickets in under ten minutes.