## TL;DR
The app still holds the old account entry, so it refuses to add it again. Remove the stale account from Authenticator, or rename it, then scan the fresh QR code from the security info page.

## The query
```text
microsoft authenticator "you already have an account" re-enrollment error
```

## Use this when
- Authenticator says an account already exists during setup
- re-enrolling after a phone reset or app reinstall
- the old phone entry was never deleted from the app

## Not for
- push notifications not arriving on an enrolled account
- QR code that will not scan at all
- admin-side MFA reset in Entra ID

## Steps
1. Open Authenticator, find the stale account entry for the organization, and remove it. Expected output: the account no longer appears in the app list.
2. In a browser, open the user's security info page and start the authenticator setup again. Expected output: a fresh QR code is displayed.
3. Scan the QR code with Authenticator and approve the test notification. Expected output: the app shows the new account and the test approval succeeds.
4. Verify the user can sign in with the new enrollment. Expected output: the MFA challenge completes on the first try.
5. If the user has a second device, repeat the enrollment there or register it as a backup method. Expected output: both devices are listed as registered methods.

## Applies to
Microsoft Authenticator on iOS and Android, Microsoft Entra ID security info, current app versions.

## Variant phrasings
### Account removed but error persists
The app cache is stale; force-stop the app or reinstall it, then retry.

### User needs the old entry kept for reference
Rename the old entry inside the app before adding the new one; the duplicate check is name-based.

## Why it happens
Authenticator keys entries by account name and will not create a duplicate. Restores and reinstalls often leave a ghost entry that the enrollment flow trips over.

## Edge cases
- If the tenant requires number matching, the test approval must be done carefully; a wrong number fails enrollment.
- Corporate-owned phones with app protection policies may need the Company Portal installed first.
- After enrollment, confirm the old device entry is removed from the user's methods to avoid confusion.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_0dyLjJmqrCORglK9tNeoOg
