MFA prompts failing block sign-in entirely. Most cases are recoverable in 5 minutes.

1. Confirm what kind of MFA

Different methods, different fixes:

  • Authenticator app push (Microsoft Authenticator, Authy, Duo) — phone notification you tap
  • 6-digit code from app — rolling code visible in the app
  • SMS — text message
  • Phone call — voice call to your registered number
  • Hardware key — YubiKey, Feitian

2. App push not arriving

Open the authenticator app manually. The notification often shows there even if you didn't see a push:

  • The app's main screen shows pending requests
  • Approve/deny from inside the app

Push delivery depends on internet on your phone — if cellular is poor or Wi-Fi is broken, push fails. Switch to the 6-digit code as a fallback:

  • Tap the account in the app
  • Use the rolling code as your MFA response

3. Time drift on the authenticator

If 6-digit codes are being rejected, your phone's clock may be drifting:

  • iPhone: Settings → General → Date & Time → Set Automatically on
  • Android: Settings → System → Date & Time → Automatic date & time on

Open the authenticator app after fixing — it should resync.

4. SMS not arriving

  • Check the phone has signal
  • Some carriers throttle short codes; try requesting a phone call instead
  • A blocked-number list on your phone could be filtering — check filtering rules
  • For international travel, SMS may not reach you — use the app

5. Lost your phone

If you've lost the phone with your authenticator app:

  • Use your backup codes (you saved them when you set up MFA, right?)
  • If you have a backup MFA method registered (e.g. a secondary phone), use that
  • Otherwise, contact IT — they'll reset MFA for you after identity verification

6. New phone — restoring MFA

When you switch phones:

  • Microsoft Authenticator with cloud backup: sign in to the app on the new phone, recover from backup
  • Google Authenticator: use the Export feature on the old phone (QR), import on new
  • Authy: signs in with your phone number, restores from cloud
  • Duo: each account needs to be re-added (Duo Restore helps for some)

If you can't restore (didn't enable backup, lost old phone), IT will reset MFA after identity verification.

7. "I'm getting prompts I didn't request"

Random MFA prompts mean someone is trying to sign in as you with your correct password.

  • Always deny the prompt
  • Change your password immediately
  • Notify IT — this is an attempted account takeover

8. Reset Microsoft Authenticator

If the app itself is broken:

If you can't get past the MFA prompt to sign in, IT has to reset it.

9. Hardware key

If your YubiKey is acting up:

  • Try a different USB port
  • For USB-C keys with USB-A laptops, use an adapter (some YubiKey models have both)
  • For NFC: hold the key against the back of the phone, not the front

When to ticket

Open a ticket if:

  • You've genuinely lost access to your MFA method
  • A specific service's MFA isn't working but others are
  • You suspect someone is attempting to sign in as you

For lost-MFA tickets, IT will need to verify your identity — be ready with employee ID and a few questions about your account.