How to Fix Microsoft Two Factor Authentication Not Working: 2026 Troubleshooting Guide

Written by: Abigail Ivy
Published on:

If your Microsoft two factor authentication is failing, the cause is often a mismatch between your device, app, and account settings.

This guide explains how to fix Microsoft two factor authentication not working with clear steps that cover Microsoft Authenticator, SMS codes, backup methods, and account recovery.

Why Microsoft two factor authentication stops working

Microsoft two factor authentication, also called multi-factor authentication or MFA, adds a second verification step after your password.

It can fail when time settings drift, the Authenticator app is out of sync, push notifications are blocked, or your phone number or recovery options are outdated.

Microsoft accounts and work or school accounts use different identity systems, so the fix depends on whether you sign in through Microsoft account, Microsoft Entra ID, or a company-managed Azure Active Directory tenant.

Understanding that difference helps narrow the problem quickly.

Check the most common causes first

  • The Microsoft Authenticator app is not connected to the correct account.
  • Your phone has no data connection or notification permission.
  • The device time and time zone are incorrect.
  • You are using an old or expired verification code.
  • Your phone number or backup email is no longer valid.
  • Your organization requires a different verification method.
  • Security defaults, Conditional Access, or account policies are blocking sign-in.

How to fix Microsoft two factor authentication not working on Microsoft Authenticator

Confirm the correct account is selected

Open Microsoft Authenticator and make sure the verification request matches the account you are trying to access.

Many people have multiple Microsoft accounts in the app, including personal Outlook.com accounts, work accounts, and school accounts.

A prompt for the wrong account will fail even if the app is working normally.

Refresh the push notification connection

If you are waiting for a push approval, verify that notifications are enabled for Microsoft Authenticator in your phone settings.

Also check that the app can use mobile data or Wi-Fi, since push requests need internet access to reach Microsoft identity services.

Use the one-time code instead of push approval

Microsoft Authenticator can generate a six-digit time-based code.

If the push prompt is delayed or not appearing, open the app and enter the current code on the sign-in screen.

Codes rotate frequently, so use the latest code shown in the app.

Sync the app account again

If the Authenticator account was restored from backup or moved to a new phone, it may need re-registration.

Remove the account from the app and add it again only if you still have another verification method available.

For work accounts, your Microsoft 365 or Entra administrator may need to reset MFA registration.

Fix time and clock-related authentication errors

Time drift is one of the most overlooked reasons for failed verification codes.

TOTP-based authenticator codes depend on the device clock being accurate within a narrow window.

  • Enable automatic date and time on your phone.
  • Set the correct time zone.
  • Restart the device after updating time settings.
  • If using a desktop authenticator or code generator, resync the system clock.

If the code works sometimes and fails at other times, clock drift is a likely cause.

This is especially common after travel, SIM changes, device resets, or battery issues on older phones.

What to do if you are not receiving SMS or phone call codes

SMS and voice call verification are still used in many Microsoft sign-in flows, but they are less reliable than authenticator app methods.

If your text or call never arrives, check the following:

  • Your phone has signal and can receive standard SMS messages.
  • You are not blocking short codes or unknown numbers.
  • The number on your account is current and correctly formatted with the country code.
  • You can receive calls if the system is using voice verification.
  • Roaming, carrier filtering, or voicemail settings are not interfering.

If you recently changed carriers or phone numbers, update your Microsoft security info as soon as you regain access.

For work accounts, ask your IT admin whether SMS verification is disabled by policy.

Reset your security info if you still have another sign-in method

If Microsoft allows you to choose another method, sign in and then update your security information.

This is often the cleanest fix when the old second factor is no longer available.

  1. Sign in using an alternate method such as a backup email, backup code, or another trusted device.
  2. Go to the Microsoft security info page for your account.
  3. Remove outdated methods such as an old phone number or lost device.
  4. Add a new Microsoft Authenticator app, phone number, or email address.
  5. Test the new method immediately before logging out.

For business accounts managed by Microsoft Entra, your administrator may require you to re-register authentication methods through the company portal or an access panel.

How to recover access when you are locked out

If you cannot approve the second factor and have no backup method, recovery depends on the account type.

For personal Microsoft accounts

Use the account recovery process and provide as much verification detail as possible.

Microsoft may ask for recent password history, billing data, or trusted contacts to confirm ownership.

Completing recovery from a familiar device and location can improve the chance of success.

For work or school accounts

Contact your organization’s help desk or identity administrator.

They can reset multifactor authentication registration, issue a temporary access pass, or clear the old device from your account.

In Microsoft Entra environments, a temporary access pass is often the fastest recovery option because it allows secure re-registration without relying on the broken factor.

Browser and device issues that can block Microsoft sign-in

Sometimes the problem is not the second factor itself, but the browser or device environment used during sign-in.

  • Clear cookies and cached authentication data in the browser.
  • Disable conflicting extensions such as ad blockers or script blockers.
  • Try an incognito or private browsing window.
  • Update the browser to the latest version.
  • Try a different browser or device to confirm whether the issue is local.

Mobile sign-in can also fail if the operating system is outdated or if background app restrictions are too aggressive.

On iPhone and Android, allow Microsoft Authenticator to run in the background and send notifications.

Account policy and security settings to review

Organizations often use Microsoft Entra Conditional Access, Security Defaults, or authentication strength policies.

These can require specific methods such as Authenticator push, number matching, or passkeys.

If you suddenly see a new challenge, the policy may have changed rather than the app failing.

Number matching is now common in Microsoft Authenticator to prevent push fatigue attacks.

If the sign-in prompt asks you to enter a number shown on the login screen, enter the exact number in the app.

A generic approval tap will not work.

Best practices to prevent future MFA problems

  • Register at least two authentication methods.
  • Keep a current phone number and backup email.
  • Enable automatic time on all devices.
  • Store recovery codes securely.
  • Keep Microsoft Authenticator updated.
  • Review sign-in methods after changing phones or carriers.
  • For work accounts, confirm your organization supports a temporary access pass or backup method.

These preventive steps reduce the chance of losing access after a device replacement, SIM swap, app reinstall, or policy change.

They also make it easier to fix Microsoft two factor authentication not working without needing a full account recovery process.

When to escalate the problem

If you have tried alternate methods, confirmed your device time, reinstalled the app, and still cannot authenticate, the issue may be at the account policy or tenant level.

At that point, Microsoft support or your organization’s identity team may need to review sign-in logs, MFA registration status, and Conditional Access rules.

For business environments, useful details include the user principal name, exact error message, sign-in timestamp, device type, and whether the failure happened in Microsoft Authenticator, SMS, voice, or a browser-based challenge.

Those details help administrators diagnose whether the failure is caused by registration, policy, or service availability.