ACCOUNTS SUPPORT GUIDE

MFA Lockout and Reset Workflow

Accounts troubleshooting guide

Knowledge Base / Accounts / MFA Lockout and Reset Workflow

Problem

Users cannot sign in because MFA is not accepting a code, their phone is lost, or authentication has been locked after repeated failed attempts.

These steps help confirm whether the issue is caused by a device change, user error, or a policy block. Always verify the user's identity before resetting any authentication factor.

Symptoms to check

  • The user cannot approve sign-in prompts or receive verification codes.
  • The account is blocked after several failed MFA attempts.
  • The user recently changed devices, numbers, or authentication apps.

Possible causes

  • Incorrect mobile number, stale authentication app, or expired backup method.
  • Conditional access or security policy is blocking sign-in.
  • Multiple failed attempts triggered temporary lockout protection.

Resolution

  1. Confirm the user has the correct account, device, and current phone number. Check whether they are using the correct app or the newest verification method.
  2. Review the sign-in logs or security portal for login failures, blocked access, or MFA challenge issues. Look for recent resets, suspicious activity, or policy enforcement.
  3. If the device is new or the number changed, confirm the user is allowed to register or reset the MFA method. Use the company-approved reset process instead of manually changing a user's sign-in setup.
  4. Reset the user's MFA method only after verifying identity and confirming the request matches the proper support process. Record the ticket reference, date, and what was reset.
  5. Have the user sign in again, complete the MFA challenge, and verify access to email, Teams, and other relevant apps before closing the ticket.

Prevention and preparation

  • Require users to register at least two verification methods when possible.
  • Encourage users to update their phone number and backup method before travel or device change.
  • Document the exact steps that should be used for approved MFA resets.

Related guides

Still not fixed? Escalate to the identity or security team and include the user’s account, failed sign-in details, and the last successful MFA event.

Submit a ticket

Last reviewed: October 2026