how to reset microsoft authenticator for a user in entra id
Resets Microsoft Authenticator for a user in Entra ID: revoke the old registration, issue a Temporary Access Pass, and re-register. Use when the user gets a new phone or the app is broken. Not a self-service flow; verify caller identity first.
TL;DR
Resetting means revoking the old Authenticator registration in Entra ID so the user can re-register on the new device. Do it from the user's Authentication methods blade, issue a Temporary Access Pass for the re-registration, and always verify the caller's identity before touching MFA.
The query
how to reset microsoft authenticator for a user in entra idUse this when
- user replaced their phone and Authenticator approvals go nowhere
- Authenticator app corrupted or reinstalled
- old device lost and must be detached from the account
Not for
- user still has the old phone working (migrate it instead)
- skipping identity verification to save time
- bulk resets (script it through Graph instead)
Steps
- Verify the caller's identity using your identity-proofing procedure before changing any MFA method. Expected output: identity confirmed and the ticket notes updated
- In Entra admin center, open the user and go to Authentication methods. Expected output: the registered methods list is visible, including the old Authenticator registration
- Delete the Microsoft Authenticator method. Expected output: the method disappears from the list
- Issue a Temporary Access Pass with a short lifetime. Expected output: a TAP code is generated
- The user signs in with the TAP and re-registers Authenticator by scanning the QR code. Expected output: the new registration appears in the methods list
- Test a sign-in with the new registration and confirm the old device is gone. Expected output: only the new device can approve
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_Np6DdQcFSS4Wmhe9jSr2UQ
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.