MFA locked out of acount

Occasional Contributor

So I recently helped someone from an other organisation (npo) which is just starting up. We submitted for the NPO program of MS. He already had a mailbox on the organisation's domain name in G Suite, we added the same account in the admin portal. He did set up MFA as suggested by MS. Couple of weeks later, NPO-submission has been approved and I assigned a M365 license to him. When he wanted to login in his browser he realized he did not transfer the Authenticator app to his new phone. He tried installing this and logging in to his account but this didn't seem to work. He kept getting the pop-up to approve in the app.
The admin center doesn't state MFA is turned on for this account so I can't reset this... I tried turning it on and off but still no change. The only options to login are the pop-up in the app or the code in the app. (see picture below)




Anyone have any idea what to do here?
There doesn't seem to be any way to reset this...

3 Replies
don't you will lock yourself.

@Josiah_wandera What should I do then? :suprised:

Go to the Azure AD blade > Users > find the user > Authentication methods > Require re-register MFA.