Lost Your Authenticator or Phone? Regaining Microsoft Account Access

hard ⏱ 30 minutes to several days Updated 2026-08-18

Official Microsoft page for this problem: account.live.com — we link it because the official flow is always the real path; this guide exists to help you get through it.

Losing the phone that holds your authenticator app — or a number that received your codes — is one of the most frustrating lockouts, because the security working against you is security you set up on purpose. Whether you can get back in depends almost entirely on what redundancy you created beforehand: a recovery code, a second verification method, or a device that’s still signed in usually means full recovery. If two-step verification was on and you have none of those, be prepared for the possibility that the account cannot be recovered — Microsoft deliberately does not provide a bypass.

Before you start

  • Check every device you own for an active session: a laptop where Outlook mail still loads, the Outlook or OneDrive app on a tablet, a signed-in browser profile, an old phone in a drawer. A live session is the single most valuable asset you have.
  • Look for a saved recovery code: a 25-character code Microsoft offers when you set up security info. Check your password manager, printed papers, and notes.
  • List every verification method that might still be on the account: old phone numbers, alternate email addresses, other devices with Authenticator.
  • If your phone was lost rather than destroyed, consider whether your carrier can move your number to a replacement SIM — restoring the phone number often restores your SMS verification method.

Step 1: Exploit any device that is still signed in

If any device still has an active session, use it before it expires — do not sign out of anything.

From the signed-in device, go to the account’s Security page and open your security info (Microsoft may still ask for a verification, but from a trusted, signed-in device it will often offer methods you can actually use). There you can:

  1. Add a new phone number or alternate email as a verification method.
  2. Set up Authenticator on a replacement phone.
  3. Generate a new recovery code and store it safely.

If the signed-in device can do all that, you’re done — the lockout never fully happens.

Step 2: Restore Microsoft Authenticator from backup

If you have a new phone, install Microsoft Authenticator and look for the option to restore from backup during setup. This works only if backup was enabled on the old phone (it stores backups against your personal Microsoft account; on iPhone it also relies on iCloud, and you must be on the same platform type for a clean restore).

A restored Authenticator brings back your account entries, though some accounts may need re-verification before push approvals work again. If backup was never enabled, restoration isn’t possible — move to Step 3.

Step 3: Sign in with an alternate method or recovery code

Go to the normal sign-in page. When the two-step prompt appears asking for a code from your lost method, look for links like “I can’t use my Microsoft Authenticator app right now” or “Use a different verification option”. Microsoft will list the other methods on file — a backup phone number, an alternate email, or entering your recovery code.

  • If a second method works, sign in, then immediately go to Security settings, remove the lost method, add replacements, and generate a fresh recovery code.
  • A recovery code substitutes for a lost method during sign-in. Each code is single-purpose: once used, generate a new one.
  • If your carrier restored your number on a new SIM, the SMS option works again — use it, then diversify your methods.

Step 4: Replace your security info (and understand the 30-day wait)

If you can’t access any existing method but can still pass basic sign-in, Microsoft may let you request replacement of your security info. Be warned: replacing all security info triggers a 30-day waiting period before the old info is removed and new info becomes usable, during which the account can be limited. Microsoft may notify your old contact methods so a legitimate owner can cancel a hijack attempt. It’s slow by design. Only start this if Steps 1–3 are truly exhausted, and note the date — you’ll regain full control after the wait.

Step 5: The account recovery form — and its honest limits

The recovery form at account.live.com/acsr lets you prove ownership with knowledge of the account: old passwords, recent email subjects, contacts you’ve written to, and billing details from Microsoft purchases. Submit from a device and network the account has seen before, fill in every field you can even approximately, and expect a response within about 24 hours.

The critical caveat: if two-step verification is fully enabled, the automated form generally cannot override it. That is intentional — otherwise 2FA would be worthless against attackers who researched you. The form is most useful when 2FA wasn’t actually on and you’ve merely lost a single verification method, or during edge cases in the replacement process. Try it, but calibrate expectations.

What NOT to do

  • Don’t pay an “account recovery service.” No third party can bypass Microsoft’s two-step verification; anyone claiming they can is lying, and you’d be handing personal data to a stranger. The recovery form is free.
  • Never share verification or recovery codes with anyone, including callers claiming to be Microsoft. Real Microsoft support never asks you to read a code aloud.
  • Ignore popups and cold calls about your “locked account.” These are scams engineered around exactly your situation.
  • Don’t submit the recovery form repeatedly with thin answers. Attempts are limited (roughly two per day) and each hasty, half-filled submission just fails. Gather stronger details between attempts.
  • Don’t sign out of working sessions “to test” your password. A live session is your lifeline; keep it alive until new security info is in place.
  • Don’t wipe or sell the old phone remotely until you’re sure you don’t need anything on it — if it might turn up, its Authenticator app is your fastest way back in.

If nothing works

If two-step verification is on, every method is gone, no session survives anywhere, and the recovery form has failed, the account is very likely permanently inaccessible. This is the deliberate cost of strong security: Microsoft cannot distinguish you from a well-informed attacker, so it refuses both.

Accept it early rather than after weeks of retries. Inventory every service that used the address for login or password reset and migrate each to an address you control — most services can verify you by other means (billing, ID, support tickets) even when email reset is unavailable. Notify regular contacts of your new address. Then rebuild with redundancy from day one: two different verification methods on separate devices, Authenticator with cloud backup enabled, and a recovery code stored in a password manager and on paper. The people who never face this problem twice are the ones who treat the recovery code as seriously as the password.

Frequently asked questions

I lost my phone with Microsoft Authenticator. Am I locked out for good?

Not necessarily. If you have a recovery code, a second verification method (backup phone number or alternate email), or a still-signed-in device, you can get back in. Without any of those, the account recovery form is the remaining path.

What is a Microsoft recovery code and where do I find mine?

It's a 25-character code you can generate in advance on your account's Security page. It substitutes for a lost verification method. You can only view or generate it while signed in, so set one up before you need it.

Can I restore Microsoft Authenticator on a new phone?

Yes, if you had cloud backup enabled in the app. Install Authenticator on the new phone and choose to restore from backup, signing in with the same personal Microsoft account (on iPhone, the same Apple account for iCloud). Without a backup, you must re-add each account manually.

Why does Microsoft make me wait 30 days after changing security info?

When you replace all your security info, Microsoft holds the change for a 30-day waiting period before old methods are removed. It's an anti-hijacking measure — it gives the real owner time to cancel a fraudulent change, but it also means you may wait if you replaced info yourself.

Does the account recovery form work for two-factor lockouts?

Only partially. If two-step verification is fully enabled on the account, the automated recovery form generally cannot bypass it — that's by design. Your realistic options are your remaining second method or your recovery code.

recover.email is not affiliated with Microsoft. This guide is informational and cannot guarantee recovery.