Guide

How to reset multi-factor authentication for a Microsoft 365 user

A user replaces their phone, does not move the authenticator app across, and is locked out of everything at once. This is the single most common ticket a small business raises. The fix is to require MFA re-registration on that account, then have the user enrol the new device at next sign-in.

What you'll see

  • "We couldn't sign you in" or a stalled approval prompt after entering the correct password
  • The Authenticator app shows no account, or shows an account that no longer generates a working code
  • The user can still sign in on an already-authenticated desktop session but not on a new device

The procedure

Step by step

  1. Step 01

    Confirm the identity of the requester

    Before touching the account, verify the person is who they say they are — a callback to a known number, a confirmation from their manager, or an in-person check. MFA reset requests are a favourite pretext for attackers, and this step is the whole security value of the process.

  2. Step 02

    Open the user in Microsoft Entra ID

    Sign in to the Microsoft Entra admin centre as a Global Administrator, Authentication Administrator or Privileged Authentication Administrator. Go to Identity, then Users, then All users, and open the affected account.

  3. Step 03

    Require re-registration of MFA

    On the user's page, open Authentication methods and choose Require re-register multifactor authentication. This clears the existing registration without deleting the account, so the next sign-in prompts the user to enrol a fresh device.

  4. Step 04

    Revoke existing sessions

    Still on the user's page, select Revoke sessions. This invalidates refresh tokens on devices that were already signed in, which matters if the old phone is lost, stolen or sold.

  5. Step 05

    Have the user enrol the new device

    Ask the user to sign in at aka.ms/mfasetup on a trusted device and follow the enrolment prompts. Recommend they add two methods — the authenticator app plus a phone number or a second device — so the same lockout does not repeat.

  6. Step 06

    Confirm and record

    Watch for a successful sign-in in the Entra sign-in logs, then record who requested the reset, who approved it, and when. If your organisation is working toward Cyber Essentials, this record is part of the evidence.

When to stop and escalate

Escalate if the account shows sign-ins from unexpected countries, if the user reports emails they did not send, or if inbox rules have appeared that forward mail externally. That is an account compromise, not a lost phone, and it needs containment first.

How AlwaysOnIT handles it

With AlwaysOnIT, the identity check and the reset both happen inside chat: the agent verifies the user against your identity provider, requests a short-lived scoped token, applies the re-registration requirement, revokes sessions and writes the whole sequence to your audit log.

More walkthroughs in the guides index, terminology in the glossary.

Get started

Open a chat. The AI picks up before the second ring — every time.

No onboarding calls. No sales process. Connect your devices and start raising tickets in under ten minutes.