New phone can’t approve sign-in requests: MFA recovery steps
For customers who replaced or reset a phone and can no longer approve sign-in prompts. This runbook helps you identify whether the issue is a missing authenticator app, lost push enrollment, wrong device time, or a changed phone number, then walks you through the safest fix.
TL;DR — If you got a new phone and sign-in approvals stopped working, the most common cause is that your multi-factor authentication (MFA, an extra sign-in check) is still tied to your old device. First try a backup method on the sign-in screen such as a recovery code, SMS, or backup email, then remove and re-add your new phone in your account's security settings or ask your admin/support contact to reset MFA for your account. Reading time: ~6 min
The scenario
It’s a normal Tuesday afternoon. You open your work app or client portal on your laptop, type your password, and the page says it sent an approval request to your phone. But you just replaced that phone this morning, and nothing arrives. You try again, then try from another browser, and now you’re stuck in a loop: password accepted, approval required, no way to approve.
Symptoms
- After entering your password, you see prompts like:
Approve sign-in request on your mobile deviceOpen your authenticator app and enter the codeWe sent a notification to your phoneVerification required
- Your new phone does not receive any push notification.
- Your authenticator app opens, but the old account is missing or shows no 6-digit code.
- A code from the app is rejected with messages such as:
Invalid codeCode expiredThe verification code is incorrect
- SMS codes do not arrive after changing your number or moving to a new SIM.
- You can still sign in on an already logged-in device, but not on new devices.
- In your account security page, the old phone or old phone number is still listed.
Likely causes
| Cause | How common | Quick check |
|---|---|---|
| MFA is still enrolled to the old phone/app | Very common | On the sign-in page, click Try another way and see whether only the old device is offered |
| Authenticator app was not transferred or restored on the new phone | Very common | Open your authenticator app and check whether the work/client account exists |
| Phone time is wrong, so app codes fail | Common | On your phone, open Settings → Date & time and confirm Set automatically is on |
| Phone number changed, so SMS/voice codes go to the old number | Common | On the sign-in page, choose SMS/voice and check which number is masked |
| Push notifications are blocked on the new phone | Sometimes | On your phone, open Settings → Notifications for the authenticator app and confirm notifications are allowed |
| Your account needs an admin/support MFA reset | Sometimes | If you have no backup method and no signed-in session anywhere, this is likely the issue |
Step-by-step diagnosis
- Check whether another sign-in method is available.
- On the sign-in page, click one of these links if shown:
Try another way
Use a different verification option
I can't use my authenticator app right now
- If you see options like
Recovery code,SMS,Email, orSecurity key, this means you can probably recover access without support. Jump to the matching fix section below. - If the only option is your old phone or an app approval you cannot access, jump to
### MFA is still enrolled to the old phone/app.
-
Check whether your authenticator app actually has the account on the new phone.
- Open the authenticator app you used before.
- Look for an entry for your work account, client portal, or company name.
- If the account entry is missing entirely, this is your problem. Jump to
### Authenticator app was not transferred or restored on the new phone. - If the account exists and shows a changing 6-digit code every 30 seconds, continue to the next step.
-
Test whether the code is failing because of phone time drift.
- On iPhone:
Settings → General → Date & Time → Set Automatically - On Android:
Settings → System → Date & time → Set time automatically - If automatic time was off, turn it on, wait 1 minute, then try signing in again.
- If codes start working, jump to
### Phone time is wrong, so app codes fail. - If not, continue.
- On iPhone:
-
Check whether SMS or voice verification is still pointing at your old number.
- On the sign-in page, choose
SMSorCall meif available. - Look at the masked number, for example:
- On the sign-in page, choose
Text a code to ***-***-4821
- If the last digits match your old number, this is your problem. Jump to
### Phone number changed, so SMS/voice codes go to the old number. - If the number is correct but no message arrives, continue.
-
Check whether the app can receive push notifications.
- On your phone, open the app settings for the authenticator app:
- iPhone:
Settings → Notifications → [Authenticator app] - Android:
Settings → Apps → [Authenticator app] → Notifications
- iPhone:
- If notifications are off, or
Background App Refresh/ battery optimization is blocking the app, turn them on and retry. - If a test sign-in now triggers a prompt, jump to
### Push notifications are blocked on the new phone. - If not, continue.
- On your phone, open the app settings for the authenticator app:
-
If you are still signed in anywhere, use that session to inspect security settings.
- From an already logged-in browser or app, open your account security page. In most providers this is under a path like:
Profile or Avatar → Account → Security
- Look for sections named:
Two-factor authentication
Multi-factor authentication
Sign-in methods
Security methods
- If you see your old phone, old number, or duplicate authenticator entries, this confirms the problem. Jump to the matching fix below.
- If you cannot access any signed-in session and have no backup method, jump to
### Your account needs an admin/support MFA reset.
Fixes
MFA is still enrolled to the old phone/app
Use a backup sign-in method first, then replace the old device entry.
- Sign in using
Try another waywith one of these methods if available:
Recovery code
SMS code
Email code
Security key
- Once signed in, open your account security page:
Profile or Avatar → Account → Security → Two-factor authentication / Sign-in methods
- Remove the old phone or old authenticator entry.
- Add the new phone by choosing the authenticator app option and scanning the QR code shown on screen.
- Save any new recovery codes somewhere safe.
If your provider offers only an admin-controlled reset, contact your admin or support team with a request like:
I replaced my phone and can no longer approve MFA prompts. Please reset or clear my MFA methods so I can enroll my new device. My username/email is: you@example.com
Verify it worked: start a fresh sign-in and confirm the prompt goes to the new phone or the new app entry generates an accepted code.
Authenticator app was not transferred or restored on the new phone
If the app is installed but the account is missing, you usually need to re-enroll it from the account security page.
- If you still have an active session on any browser/device, open:
Profile or Avatar → Account → Security → Two-factor authentication / Sign-in methods
- Choose
Add authenticator app,Set up app, or similar. - Open the authenticator app on your new phone and scan the QR code.
- Enter the 6-digit code from the app to confirm setup.
- Remove the old app/device entry if it is still listed.
If you do not have any active session, use a recovery code or another sign-in method first. If you have none, go to ### Your account needs an admin/support MFA reset.
Verify it worked: the authenticator app shows a changing 6-digit code for the account, and the next sign-in accepts that code.
Phone time is wrong, so app codes fail
Time-based one-time passwords (TOTP, a 6-digit code that changes every 30 seconds) fail if your phone clock is off.
- Turn on automatic time:
- iPhone:
Settings → General → Date & Time → Set Automatically
- Android:
Settings → System → Date & time → Set time automatically
- If your phone has a separate time zone setting, also enable automatic time zone.
- Force-close and reopen the authenticator app.
- Wait for the next code rotation, then try again.
Verify it worked: the next 6-digit code is accepted without an Invalid code or Code expired error.
Phone number changed, so SMS/voice codes go to the old number
- If you can sign in with another method, update your number in:
Profile or Avatar → Account → Security → Sign-in methods / Phone
- Remove the old number.
- Add the new number and complete the verification text or call.
- If your provider allows it, add an authenticator app too so you are not blocked by future number changes.
If you cannot sign in because the only available method is the old number, contact your admin/support team and ask for your phone verification method to be removed or updated.
Verify it worked: the sign-in page shows the masked digits of your new number, and the test code arrives there.
Push notifications are blocked on the new phone
- Enable notifications for the authenticator app:
- iPhone:
Settings → Notifications → [Authenticator app] → Allow Notifications
- Android:
Settings → Apps → [Authenticator app] → Notifications → Allow
- Disable battery restrictions for the app if your phone has them:
- Android path often looks like:
Settings → Apps → [Authenticator app] → Battery → Unrestricted
- Open the authenticator app once manually and keep it signed in if the app requires that.
- Retry the sign-in.
If push still does not arrive, use the app's manual 6-digit code option if available.
Verify it worked: a new sign-in attempt produces a phone notification within a few seconds.
Your account needs an admin/support MFA reset
If you have no backup method, no active session, and the old phone is gone, an admin reset is usually the only path.
⚠️ An MFA reset signs you out of protected sessions in some systems. If you are currently signed in somewhere important, check with your admin before they clear your security methods.
Send your admin or support team a short request:
Subject: MFA reset needed after phone replacement
I replaced my phone and no longer have access to the device/app used for sign-in approvals. I cannot use any backup verification method. Please reset my MFA/sign-in methods so I can enroll my new phone.
Account email/username: you@example.com
Best callback number: +1 555 010 1234
After they confirm the reset, sign in again and enroll your new phone immediately from:
Profile or Avatar → Account → Security → Two-factor authentication / Sign-in methods
Verify it worked: after the reset, the sign-in flow lets you set up a new app/phone instead of asking for approval from the old device.
Prevention
- Save recovery codes when you set up MFA, and store them outside your phone. For example, copy them into your password manager's secure notes:
Account: Client Portal
Recovery codes:
- XXXX-XXXX
- XXXX-XXXX
- XXXX-XXXX
- Add at least two sign-in methods on your account security page:
Profile or Avatar → Account → Security → Add method
Good combinations are:
Authenticator app + recovery codes
Authenticator app + security key
Authenticator app + verified phone number
- Before replacing a phone, sign in and remove/re-add the authenticator app from the old device while you still have it:
Profile or Avatar → Account → Security → Two-factor authentication / Sign-in methods
- Turn on automatic date/time on phones used for app-based codes:
iPhone: Settings → General → Date & Time → Set Automatically
Android: Settings → System → Date & time → Set time automatically
- Keep one trusted device signed in until the new phone is fully enrolled. That gives you a recovery path if the migration fails.
- If your organization has an IT/admin contact, keep their MFA reset process documented in your internal notes, including the exact request template and expected identity check steps.
This article was written by an AI system and published pending human review. Verify anything you intend to act on.
Have a project in mind?
Get an instant AI price estimate for it, or talk directly to our team.
One email a month on what we learn building with AI