TS-002: Replacement phone prevents MFA sign-in

Restored Microsoft 365 access after a replacement phone left the user unable to satisfy MFA. First-line triage established the permission boundary, the authentication-method change was escalated under least privilege, and access was validated after Microsoft Authenticator re-registration through Entra sign-in logs.

Scenario

Kate Jones contacted the Service Desk after receiving a replacement phone. Her password was accepted, but sign-in required an authenticator-app code from the previous device, preventing access to Microsoft 365. The incident was treated as a single-user MFA issue with low impact but high urgency.

ServiceNow Ticket

ServiceNow incident initially assigned to Chloe Bennett for Kate Jones' MFA issue
Figure 1Incident classified with the correct service, offering and configuration item, then assigned to first-line support.

Investigation

Signing in as Kate reproduced the issue: Microsoft 365 requested a code from an authenticator app. This confirmed that the password was accepted and that the failure occurred at the MFA stage.

Microsoft sign-in prompt requesting an authenticator app code for Kate Jones
Figure 2The sign-in flow reached MFA but required a code from the previous phone.

The Service Desk account could reach Kate's Entra authentication-methods page but could not view or manage the underlying methods. This established a clear permission boundary and justified escalation instead of granting broader identity-administration permissions to first line.

Entra authentication methods page showing that the Service Desk account cannot access the data
Figure 3The first-line account reached its permitted boundary in Microsoft Entra ID.
ServiceNow work note documenting escalation to Second Line Support
Figure 4The escalation reason was recorded before reassignment to Kristian Nietzold.

Chloe documented the identity check, the successful password stage and the authentication-method permission limitation. The ticket was then reassigned to Second Line Support for the privileged MFA action.

Fix Applied

Second Line reviewed Kate's authentication methods and identified an existing Software OATH token with an OATH TOTP code as the default sign-in method. This matched the code challenge reproduced during investigation.

Kate Jones' Entra authentication methods showing a software OATH token before the fix
Figure 5The obsolete software OATH method was confirmed before remediation.
Kate Jones' Entra authentication methods showing no usable methods after reset
Figure 6The previous MFA method was removed, ready for a clean registration.

The old method was cleared and MFA re-registration was required. Entra then showed no usable authentication methods, confirming that the previous registration was no longer available for sign-in.

Kate registered Microsoft Authenticator on the replacement phone. Entra showed Microsoft Authenticator as a usable notification method and as the default sign-in method.

Kate Jones' Entra authentication methods showing Microsoft Authenticator registered on the replacement phone
Figure 7Microsoft Authenticator notification was successfully registered on the replacement device.

Validation

Entra sign-in logs showed earlier interrupted attempts followed by a successful interactive sign-in with sign-in error code 0. This provided administrative evidence that access had been restored.

Kate Jones' Entra sign-in logs showing a successful sign-in after MFA remediation
Figure 8Entra sign-in logs confirmed a successful sign-in after the MFA registration sequence.

Resolution

The incident was resolved by Kristian Nietzold using the code Solution provided. The resolution notes recorded removal of the previous method, Microsoft Authenticator re-registration, successful sign-in-log validation and user confirmation that access was restored.

ServiceNow resolution information documenting the MFA reset and successful validation
Figure 9The final resolution captured the privileged action, validation evidence and restored access.

Summary

  • I classified a P3 Moderate incident using the correct category, service, service offering and configuration item.
  • I reproduced the MFA code challenge and confirmed that the user's password was accepted.
  • I demonstrated least-privilege troubleshooting by escalating when the Service Desk account could not manage Entra authentication methods.
  • I documented the escalation in ServiceNow and transferred ownership to Second Line Support.
  • I identified and cleared the obsolete software OATH method, then required MFA re-registration.
  • I registered Microsoft Authenticator on the replacement phone and validated the result using Entra sign-in logs.
  • I resolved the incident with a clear resolution code and clear resolution notes.