Re-enroll Microsoft Authenticator on a new phone (employees)

Summary

Re-enroll Microsoft Authenticator when you replace, reset, lose, or no longer use the phone registered for multifactor authentication (MFA). You can complete the change yourself if your old phone or a backup method still works. Otherwise, Technology Services and Support must verify your identity before resetting MFA.

Use this when: You have a new or replacement phone, reset your phone to factory settings, or lost access to the enrolled phone.

Audience: District faculty and staff.

Time required: About 10 minutes when an existing method works. Allow additional time when identity verification is required.

Students: MFA is not currently required for student accounts, so this procedure does not apply to students.

Choose your path

You still have the old phone or a working backup method

Use Path 1. You can enroll the new phone yourself.

You cannot use the old phone or any backup method

Use Path 2. Technology Services and Support must verify your identity before MFA can be reset.

If the old phone was lost or stolen: Do not approve any unexpected authentication request. Follow Path 2 if you cannot immediately remove the old method yourself.

Path 1: Use the old phone or a backup method

Use this path when you can approve a sign-in on the old phone or receive an SMS message or telephone call through a registered backup number.

  1. Install Microsoft Authenticator on the new phone. Open the App Store on an iPhone or Google Play on an Android phone. Search for Microsoft Authenticator and confirm that the publisher is Microsoft Corporation.
  2. Open the MFA setup page on a computer. Go to Microsoft MFA setup and sign in with your Solano email address and password.
  3. Complete the current MFA request. Approve it on the old phone, or select the option to use another method and complete an available SMS message or telephone call.
  4. Add Microsoft Authenticator. Select Add sign-in method, select Authenticator app, and then select Add. Continue until a QR code appears.
  5. Connect the new phone. On the new phone, open Microsoft Authenticator, select the plus (+) button, select Work or school account, and then select Scan a QR code. Scan the QR code displayed on the computer.
  6. Approve the test request. Enter or select the matching number in Microsoft Authenticator when prompted, and then select Approve.
  7. Test the new phone again. Open a new private or incognito browser window and sign in to a District service. Confirm that the new phone receives and approves the request.
  8. Remove the old Microsoft Authenticator method. Return to the sign-in-methods page and delete the Authenticator entry associated with the old phone. Remove it only after the new phone passes the sign-in test.
  9. Confirm your backup telephone number. Make sure the number is current. Update and verify it if your telephone number also changed.

Success: The new phone receives and approves a test sign-in, the old Authenticator method is removed, and the backup telephone number is current.

Path 2: Request help when no method works

You cannot re-enroll Microsoft Authenticator yourself when you cannot use the old phone or a registered backup method. Identity verification protects your account from unauthorized MFA changes.

  1. Submit a Password or Login Help request.
  2. Select the account. For Account or System, select College Computer or Network Account.
  3. Select the problem type. For Login Problem Type, select MFA, verification code, or phone problem.
  4. Select the MFA issue. For MFA Issue Type, select Lost or Replaced Phone.
  5. Provide contact information. Include a telephone number where Technology Services and Support can reach you and the best time for a call. Do not include passwords or verification codes.
  6. Complete identity verification. An agent will contact you. You may be asked to verify through your supervisor or present an approved photo ID in person.
  7. Enroll the new phone. After the agent resets your MFA methods or provides approved enrollment access, follow Set up Microsoft Authenticator for Solano sign-in (employees).

If it does not work

The old phone is broken, but you still have the same SIM

Move the SIM to the new phone if your mobile carrier and device support it. If the registered backup number is unchanged, use an SMS message or telephone call to complete Path 1.

The old phone receives calls but not Authenticator notifications

On the sign-in screen, select the option to use another method. Choose an available SMS message or telephone call, and then continue with Path 1.

The QR code will not scan

Increase the computer screen brightness, move the phone slightly farther from the screen, and confirm that Microsoft Authenticator has camera permission. For more troubleshooting, use Set up Microsoft Authenticator for Solano sign-in (employees).

Technology Services and Support cannot verify your identity remotely

Bring an approved photo ID to the Technology Services and Support office during business hours. 
Mon – Fri: 8:00 AM to 4:30 PM (excluding holidays)
Weekends & Holidays: Closed
Location: Library & Learning Resources 100 (PDF)

Related articles and guidance

Get help

If Path 1 does not work, submit a Password or Login Help request and select New Phone Needs Enrollment as the MFA issue type.

If you are using Path 2 and have not received the verification call within one business day, reply to the existing request instead of opening another request.

Protect your information: Never include your password, verification code, QR code, Temporary Access Pass, recovery code, or a copy of your identification in the request unless an authorized agent provides an approved secure method.

Print Article

Related Articles (2)

Install Microsoft Authenticator, enroll it for employee MFA, add a backup method, and learn how to approve Solano sign-ins.
Troubleshoot missing Microsoft Authenticator notifications or verification codes, denied or expired requests, app lock, blocked sign-ins, and unexpected MFA prompts.