MFA prompts failing block sign-in entirely. Most cases are recoverable in 5 minutes.
1. Confirm what kind of MFA
Different methods, different fixes:
- Authenticator app push (Microsoft Authenticator, Authy, Duo) — phone notification you tap
- 6-digit code from app — rolling code visible in the app
- SMS — text message
- Phone call — voice call to your registered number
- Hardware key — YubiKey, Feitian
2. App push not arriving
Open the authenticator app manually. The notification often shows there even if you didn't see a push:
- The app's main screen shows pending requests
- Approve/deny from inside the app
Push delivery depends on internet on your phone — if cellular is poor or Wi-Fi is broken, push fails. Switch to the 6-digit code as a fallback:
- Tap the account in the app
- Use the rolling code as your MFA response
3. Time drift on the authenticator
If 6-digit codes are being rejected, your phone's clock may be drifting:
- iPhone: Settings → General → Date & Time → Set Automatically on
- Android: Settings → System → Date & Time → Automatic date & time on
Open the authenticator app after fixing — it should resync.
4. SMS not arriving
- Check the phone has signal
- Some carriers throttle short codes; try requesting a phone call instead
- A blocked-number list on your phone could be filtering — check filtering rules
- For international travel, SMS may not reach you — use the app
5. Lost your phone
If you've lost the phone with your authenticator app:
- Use your backup codes (you saved them when you set up MFA, right?)
- If you have a backup MFA method registered (e.g. a secondary phone), use that
- Otherwise, contact IT — they'll reset MFA for you after identity verification
6. New phone — restoring MFA
When you switch phones:
- Microsoft Authenticator with cloud backup: sign in to the app on the new phone, recover from backup
- Google Authenticator: use the Export feature on the old phone (QR), import on new
- Authy: signs in with your phone number, restores from cloud
- Duo: each account needs to be re-added (Duo Restore helps for some)
If you can't restore (didn't enable backup, lost old phone), IT will reset MFA after identity verification.
7. "I'm getting prompts I didn't request"
Random MFA prompts mean someone is trying to sign in as you with your correct password.
- Always deny the prompt
- Change your password immediately
- Notify IT — this is an attempted account takeover
8. Reset Microsoft Authenticator
If the app itself is broken:
- Sign in to aka.ms/mfasetup
- Re-register your account by scanning the QR code
If you can't get past the MFA prompt to sign in, IT has to reset it.
9. Hardware key
If your YubiKey is acting up:
- Try a different USB port
- For USB-C keys with USB-A laptops, use an adapter (some YubiKey models have both)
- For NFC: hold the key against the back of the phone, not the front
When to ticket
Open a ticket if:
- You've genuinely lost access to your MFA method
- A specific service's MFA isn't working but others are
- You suspect someone is attempting to sign in as you
For lost-MFA tickets, IT will need to verify your identity — be ready with employee ID and a few questions about your account.