M365 MFA with Microsoft Authenticator OTP
Microsoft Authenticator generates time-based one-time passwords (TOTP) for your M365 account. Every 30 seconds, the app shows a new 6-digit code you’ll enter when signing in.
Prerequisites
Section titled “Prerequisites”- An iPhone or Android phone
- Microsoft Authenticator app installed (iOS App Store | Google Play Store)
Setting Up Microsoft Authenticator
Section titled “Setting Up Microsoft Authenticator”-
On your computer, go to https://aka.ms/mysecurityinfo and sign in with your Microsoft 365 account.
-
Click + Add sign-in method.
-
From the dropdown, select Authenticator app and click Add.
-
Click Next on the “Start by getting the app” screen (you already have it).
-
On the “Set up your account” screen, click Next.
-
Microsoft will display a QR code. Don’t scan it yet — first open the Authenticator app on your phone.
-
In Microsoft Authenticator on your phone:
- Tap the + button (or menu icon → Add account)
- Select Work or school account
- Tap Scan QR code
-
Point your phone camera at the QR code on your computer screen. The app will automatically recognize it.
-
Your account will be added to Authenticator. You’ll see your organization name and email, with a 6-digit code that refreshes every 30 seconds.
-
Back on your computer, click Next.
-
Microsoft will ask you to enter the current code from the app to verify setup. Type the 6-digit code shown in Authenticator and click Next.
-
You’ll see a success message. Click Done.
Using Microsoft Authenticator OTP
Section titled “Using Microsoft Authenticator OTP”When signing into M365:
-
Enter your email and password as normal.
-
When prompted for verification, select Use a verification code (or it may go directly to the code entry screen).
-
Open Microsoft Authenticator on your phone.
-
Find your M365 account and note the 6-digit code displayed.
-
Type the code into the verification field on your computer.
-
Click Verify to complete sign-in.
Enabling Push Notifications (Optional)
Section titled “Enabling Push Notifications (Optional)”Microsoft Authenticator also supports push notifications like Outlook. If you prefer tapping “Approve” instead of typing codes:
-
Find Microsoft Authenticator in your sign-in methods list.
-
Click Change or look for notification settings.
-
Enable push notifications for passwordless sign-in or approval requests.
With push enabled, you get the best of both worlds — quick approvals when available, with OTP codes as backup.
Troubleshooting
Section titled “Troubleshooting”Code not working?
- Ensure you’re entering the code for the correct account (check the email address in Authenticator)
- Verify your phone’s time is set automatically — TOTP codes depend on accurate time
- Wait for a fresh code if the current one is about to expire
Account not showing in Authenticator?
- Try removing and re-adding the account
- Ensure you selected “Work or school account” during setup
Lost access to your phone?
- Contact your IT administrator to reset your MFA
- If you set up backup methods (phone number, alternate email), use those at https://aka.ms/mysecurityinfo