SOLVED

Issues with Microsoft Authenticator not popping up Approval message

Steel Contributor

We have recently implemented MFA with a conditional access policy. We turned off the ability to receive texts/calls and are forcing the Authenticator app. This is causing issues when users need to re set up the account in the Authenticator app. I have had multiple scenarios this week where the Microsoft Authenticator app has stopped displaying the approve/deny message. The end users try to fix the issue themselves and will remove their accounts from the app and try to reenroll by going to myapps.microsoft.com and restarting the setup process. The problem lies in that even though they are visiting the portal from devices that are excluded from MFA via conditional access (Compliant/Hybrid AD Joined) the myapps.microsoft.com portal is still enforcing MFA to log in. Since they have removed their account from the application they can not authenticate to the portal. There is no alternate method since Phone/Text are disabled. 

 

In order to get the end user back into the portal I have to go to the regular MFA Setup page, enable phone calls or texts, enable and enforce MFA on the end user, and they can finally get in to re-set up the account. 

 

All of this could be fixed with a one time bypass for cloud! 

39 Replies

@Robert Woods I have been using the Authenticator App for some time (shared Microsoft 365 file between another business and myself) and never had any issues until I upgraded from an Iphone 8 to an Iphone 13.  

It says its sending me an approval, but nothing ever comes through.  A couple of times, it even tells me i've denied access - which of course I'm not seeing any popups so confused for sure on that one.  I've even attempted to add the 6 digit code that is under my account and it says its not a valid code.  

I've uninstalled, reinstalled, rescanned the QR Code, etc.  Nothing seems to be working.  I've even been in hte apple store for a few hours and they couldn't figure it out either.  

 

Need advise as this is a file I use on a pretty regular basis for my job.  

 

I was able to solve the issue by just disabling iCloud backup inside the app settings and re-enabling it. For me it was not required to remove settings or the whole app to solve it.

@Robert WoodsWhen you connect an account to Microsoft Authenticator and enable multi-factor authentication, you will be able to sign in to your account via a code that shows up on the Authenticator app. The code changes every time Uk49s the timer exhausts. Because it’s a multi-factor authentication process, some websites will require you to sign in to your account using your password first.

It Looks Very Good.

Where do I change the priority to higher so that I receive the notification?

I was able to solve the issue by just disabling iCloud backup inside the app settings and re-enabling it. For me, it was not required to remove settings or the whole mobilepondit app to solve it.

 

Users can sometimes receive direct ‘Approve’ notifications on their Microsoft Authenticator app while logging in using multi-factor authentication. In such cases, all they have to do is tap on ‘Approve’ and the log-in process will be complete. There’s no need to enter codes. Organizations can enable this process for their employees. While signing in, you’ll see a message that a notification has been sent to your Authenticator app and you’ll have to ‘Approve’ it. But here’s where the issue is showing up:smile: Users aren’t getting approve notifications of any kind. So, they are stuck trying to log into the account.

@Robert Woods i tried all the steps you provided, i was able to log back in to mfa settings to restart the process , however im still stuck in step 2 because im still not getting the approval message to continue.. They tried to revoke my mfa to start all over again but still the same.. 

@Robert Woods so I had to change the number to another phone to get the code and then it said that bc I have tried to many times it still wouldn't let me log into my account!! Which has been very aggravating blog crime news bc it's prevented me from not just all my important emails, but also from being able to get into my HP Desktop also!

@aamiraltaf @Robert Woods I am also having the same issue. Recently got a new iPhone and erased all the data from my old phone. Attempted to log into my work account through Outlook, was prompted to authenticate my login through the Microsoft Authenticator App but no approve/deny message popped up. It’s also preventing me from accessing my account remotely on my work laptop because it’s asking me to authenticate my access through the app but no notification message is popping up. 

To turn off the wifi/wi-fi really did the trick for me for my android device. Thank you!

@Robert Woods Honestly, I am living in this nightmare from the last September, when I got a new corporate account and laptop. The Authhenticator in Windows requests to authenticate in the App, which IS NOT EXISTENT!

There are no devices registered in the account to authenticate at, except the only laptop I am using.

I installed the Authenticator App on my Android, added the corp. account manually, so the mobile appeared at myaccount.microsoft.com. But it still does not send me requests to authenticate.

And on every problem it tells: "Don't have an app? Do you want to authenticate the other way? Then authenticate the other way in your Authentocator app"

And no support! Our admin mailed the support dept. 3 times, they said they will contact, and NOTHING! Silence!

 

If I get my hands on the one who designed it, he will not survive, get my word.

@Martin_Durec This was my problem and fixed it for me. Thanks so much! It was driving me mad.

If I remember correctly, I managed to solve this by deregistering the device and registering it back again.

 

Anyway, really annoying bug

@Vlad_Bara 

 

How can you deregister something NOT REGISTERED?

It requests the Authenticator authentication, when there is THE ONLY laptop in the list, and nothing more!

I tried adding another Android device in the account cabinet manually. The accaunt finally appeared "greyed" on that device in the list of Authenticator accounts. But it still does not receive requests. Neither from the corporate IP, nor when I am connected to the mobile network.

 

The most awful here is that  Microsoft support always promices to contact and does NOTHING.

 

This nuiscance, MS Authenticator, should be recalled, and the manager behind its release should be terminated.  

It is a pure sabotage to any business activity!

 

This post is from 2018, and it characterizes the Authenticator as the worst security software on the planet. Nothing was done to fix the issue!

@Robert Woods I have my notifications for the Authenticator app already turned on. However, it still didn't show the message, and only showed it when I pressed check for notifications and it came up immediately? is there any way to fix this?

 

Hi, I am trying to get to my account for the licenses that we have purchased in my company but I also changed mobile phone. So, when I try to login in the pc it requests to check authenticator in my phone and vice versa. Can someone help me?
100% agree with you, These setups are supposed to make our life easier, so that we can focus on creative things at work. But NO , Microsoft has other ideas .
This is the worst product from MS in a long time ,

Dear MS please stop this app and make something easier to us to setup , I am trying to configure this in my new phone and it's a nightmare. Authenticator App shows some random number and ask me to approve from Authenticator App , but no notification comes in my other phone's App . Do you have some developers working on these issues which are being reported by us? I am forced to use your Apps because my organization says so , wish I had other options !
I have run into this sooo many times, I just wrote this VERY short article (with screenshots) for my tech's (and a few of our clients) on how to change the Authenticator from having you type the auth code into a webpage, to having the MS Authenticator appopup prompt you for the code on the screen: https://www.urtech.ca/2023/11/solved-microsoft-authenticator-not-popping-up-approval-prompt/

I hope this helps others :)

My Authenticator app only works maybe 1 out of every 10 times (yes you read that correctly). I normally just have to send a text as I would say at this point the Authenticator app just DOESN'T WORK AT ALL. Which is very frustrating because it's the first/default option you get for two factor authentication, whereas I would prefer to just get a text because the Authenticator app doesn't work. I do not get approval messages to enter in the numbers rarely ever. 

@URTechDotCa 

This will not work, because the problem is not in the app, but in the account server.

The server tries to send an auth request to non-existing devices. And when trying to register a device it does not appear in the list, neither the app gets an active record with options. When trying to delete such device from its app, only then it may finally appear as a disfunctional device in the device list at the server. So the only option is to call it "stolen" and even then, the server will keep asking to authenticate on some non-existing device.

 

The app/web dialog offers you an option "when authenticator is not available", but it leads again to the authenticator itself in the loop.

 

And yes, you can not get into the "security info" section, because it requires to authenticate in the app.

 

Absolutely ridiculous crapware instead of claimed security, creating only troubles.