Microsoft Authenticator error 500121 can block your login even after you enter the correct password. You complete the first step, but the MFA verification suddenly fails leaving you locked out of Microsoft 365, Entra ID, or critical work apps.

In most cases, this error is not a server issue. It happens due to time sync problems, blocked accounts, or broken MFA setups. In some cases the Authenticator app shows nothing at all: no push notification arrives and no number match screen appears, leaving you with no way to complete the MFA step. However you can fix it in minutes using the exact steps below.
What Is Microsoft Authenticator Error 500121?
When you see error 500121, the authentication handshake between your device and Microsoft’s servers failed after your password was accepted. The error screen shows:
- Error Code: 500121
- Request ID – save this if you contact Microsoft Support
- Correlation ID – save this if you contact Microsoft Support
- Timestamp of the failed attempt
Important: Error 500121 is almost never caused by a Microsoft server outage. It is a client-side or policy problem you can fix yourself in most cases. Verify Microsoft service health at status.office.com to rule out an outage first.
Why Does Error 500121 Happen?
| Root Cause | Who Is Affected |
|---|---|
| Device clock is out of sync (even by 60+ seconds) | Any user |
| You tapped “Not me” or denied an MFA push notification | Any user |
| The Authenticator app’s shared MFA secret is corrupted | Any user |
| Authenticator app is outdated | Any user |
| Account email address or domain was changed (UPN mismatch) | Any user who recently changed their Microsoft account email |
| A Conditional Access policy blocks the device, location, or risk score | Work/school accounts |
| A Temporary Access Pass (TAP) expired or was already used | Work/school accounts |
| Microsoft Identity Protection flagged the sign-in as high risk | Work/school accounts |
| The user account is blocked in Entra ID or Microsoft 365 Admin Center | Work/school accounts |
8 Fixes for Microsoft Authenticator Error 500121
Work through these in order. Fixes 1 and 2 resolve the issue for most users.
Fix 1: Sync Your Device Time (Most Common Fix)
Error 500121 is most often caused by clock drift. Microsoft Authenticator uses time-based one-time passwords (TOTP) with a 30-second validity window. If your phone’s clock is even 60 seconds off, every code you generate will be rejected.
On Android:
- Go to Settings → General management → Date and time
- Enable Automatic date and time and Automatic time zone
- Restart your device
On iOS (iPhone / iPad):
- Go to Settings → General → Date & Time
- Enable Set Automatically
- Restart your device
Quick test (Android only): Open Microsoft Authenticator → tap your account → tap Correct time for codes → Sync now. The app will flag any detected drift immediately.
After syncing, retry sign-in before moving to the next fix.
Fix 2: Remove and Re-Add Your Account in Authenticator
Re-registering refreshes the shared MFA secret between your device and Microsoft. This resolves most persistent 500121 errors that time sync alone does not fix.
If you recently changed your Microsoft account email address or your organisation changed your domain, the Authenticator app is still linked to your old address (UPN mismatch). Removing and re-adding the account with the new email corrects this immediately.
Warning: Do not remove the account from Authenticator until you confirm access to mysignins.microsoft.com via an alternate method (SMS, email, or a trusted PC).
- On a PC or trusted device, sign in to mysignins.microsoft.com/security-info using an alternate method such as SMS
- Remove the existing Authenticator entry
- Select Add sign-in method → Authenticator app
- Open Microsoft Authenticator on your phone
- Tap Add account and scan the new QR code
Fix 3: Unblock the User Account – Admins Only
Tapping “Not me” during an MFA push notification triggers Microsoft’s Fraud Alert or Report Suspicious Activity feature, which can automatically block the account. Standard MFA resets will not fix this until the block is lifted.
To unblock via Microsoft Entra Admin Center:
- Go to entra.microsoft.com
- Navigate to Protection → Multifactor Authentication → Block/unblock users
- Find the affected user and click Unblock
To unblock via Microsoft 365 Admin Center:
- Go to admin.microsoft.com
- Navigate to Users → Active users and select the affected user
- Click Unblock sign-in, uncheck Block this user from signing in, and save
Note: Deleting authentication methods and issuing Temporary Access Passes will keep failing if the underlying block is not cleared first. This is the most commonly missed step in persistent 500121 cases.
Fix 4: Diagnose With Entra Sign-In Logs – Admins Only
Before making any policy changes, read the sign-in logs to find the precise failure reason. This prevents guesswork and reveals Conditional Access or Identity Protection blocks immediately.
- Open entra.microsoft.com
- Go to Monitoring & Health → Sign-in logs
- Filter by: Sign-in error code: 500121 and the affected Username
- Open the failed sign-in entry and read the Failure reason field
Common failure reasons you will see:
| Failure Reason in Log | Correct Fix |
|---|---|
| Strong authentication was denied | Fix 3 – unblock the account |
| Conditional Access policy requires compliant device | Fix 5 – review CA policies |
| Sign-in blocked by Identity Protection | Fix 5 – review risk policies |
| Authentication timed out | Fix 1 – time sync |
| MFA method not configured | Fix 6 – reset MFA registration |
Detailed sign-in log filtering requires Microsoft Entra ID P1 or higher. The Report Reader role is the minimum role required to access this data.
Fix 5: Review Conditional Access Policies – Admins Only
If sign-in logs show a Conditional Access or Identity Protection block, review and temporarily adjust the relevant policy:
- In Entra Admin Center, go to Protection → Conditional Access → Policies
- Identify the policy blocking the user (the sign-in log will name it)
- Check if the block is due to: device non-compliance, non-approved network location, or a High risk sign-in score from Identity Protection
- Temporarily exclude the affected user, or issue a Temporary Access Pass (TAP) so they can re-register MFA from a trusted location
Geographic location note: If users in your tenant are accidentally tapping “Not me” because the location shown in the MFA push looks unfamiliar, go to Security → Authentication Methods → Policies and review the Show geographic location in push notifications setting. The location shown may not match the user’s exact city, which causes false fraud reports.
Fix 6: Reset MFA Registration – Admins Only
Use this when the user is partially locked out and can still complete some form of authentication (e.g., SMS).
- In Entra Admin Center, go to Users → All users and select the affected account
- Click Authentication methods
- Click Require re-register multifactor authentication
- On the user’s next sign-in, they will be prompted to set up MFA from scratch
If the user cannot complete any authentication method at all, generate a Temporary Access Pass (TAP):
- In the user’s Authentication methods panel, click Add authentication method → Temporary Access Pass
- Set an appropriate validity window (e.g., 1 hour)
- Provide the TAP to the user – they use it in place of MFA for one session to re-register
Fix 7: Use Alternate MFA Methods (SMS or Phone Call)
If your organisation has alternate verification methods configured and the Authenticator app is failing:
- During sign-in, click Other ways to sign in or I can’t use my Microsoft Authenticator app right now
- Choose Text a code or Call my phone
- Complete sign-in, then visit mysignins.microsoft.com/security-info to fix the Authenticator registration
Best practice: Always register at least two MFA methods (Authenticator app + SMS) so one is always available as a fallback.
Fix 8: Update or Reinstall Microsoft Authenticator
An outdated or corrupted Authenticator app can silently fail to generate or deliver MFA codes without displaying any obvious error.
- Open the Play Store (Android) or App Store (iOS) and search for Microsoft Authenticator
- Tap Update if available
- If the update does not help, uninstall the app completely and reinstall it
- Re-add your account using a fresh QR code from the Security Info page (see Fix 2)
Warning: Uninstalling Authenticator removes all accounts stored in the app. Confirm you have an alternate MFA method or backup codes before uninstalling.
Browser-Specific 500121 Issues
If MFA prompts fail only in a web browser during Microsoft 365 sign-in:
- Clear browser cache and cookies: Settings → Privacy → Clear browsing data
- Confirm JavaScript is enabled in your browser
- Disable ad blockers or script-blocking extensions temporarily
- Avoid private/incognito mode – Microsoft’s MFA flow depends on session cookies
- Try a different browser (Edge, Chrome, Firefox) to isolate the problem
If You Are the Only Administrator
Being the sole admin with error 500121 is a serious lockout scenario. Try these steps in order:
- Sign in from a previously trusted device or network – Microsoft may skip the full MFA challenge for a known device
- Use any backup MFA method already on the account (SMS, backup email, FIDO2 hardware key)
- Use a Temporary Access Pass (TAP) if one was previously configured
- Contact Microsoft Support at support.microsoft.com and request tenant recovery. Have ready:
- Error code: 500121
- Request ID (from the error screen)
- Correlation ID (from the error screen)
- Timestamp of the failed sign-in
- Your company name and billing details
- An alternate email address for identity verification
When you call, select business account then technical support. Ask to be transferred to the Data Protection Team directly and explain you are the sole administrator locked out of your tenant. The Data Protection Team is the only team authorised to manually reset MFA for a sole admin account. Do not accept a redirect to general support – only the Data Protection Team can action this request.
- Create a second emergency admin account in Entra ID. Configure it with a hardware FIDO2 key and a separate backup email MFA. Store credentials securely – use it only in break-glass scenarios like this one.
Quick-Reference: Match Your Situation to the Right Fix
| Your Situation | Most Likely Cause | Go To |
|---|---|---|
| MFA codes are rejected every time | Clock drift | Fix 1 |
| You tapped “Not me” or denied a push | Account blocked by Fraud Alert | Fix 3 |
| MFA fails after getting a new phone | Corrupted or expired MFA secret | Fix 2 |
| MFA fails after changing your email or domain | UPN mismatch in Authenticator app | Fix 2 |
| Login fails from a specific device or location | Conditional Access policy | Fix 4 → Fix 5 |
| No MFA push notification arrives | App outdated or notification blocked | Fix 8 |
| Error happens in browser only | Browser cache or cookies | Browser fix section |
| Admin locked out with no backup method | Sole admin lockout | Sole admin section |
| User completely locked out | Fraud Alert block | Fix 3 first, then Fix 6 |
How to Prevent Error 500121 From Returning
- Keep Microsoft Authenticator updated automatically – enable auto-updates on your phone
- Always register at least two MFA methods on every account
- Keep your phone’s date and time set to automatic
- Never tap “Not me” unless you are certain the prompt is fraudulent – doing so triggers an Identity Protection block
- If you deny a prompt due to suspected phishing, report it to your IT admin immediately so they can review the sign-in log and clear any resulting block
- Create and store backup MFA codes via Security Info before you need them
- For organisations: create at least one break-glass emergency admin account protected with a hardware FIDO2 key
Related Microsoft Authenticator Error Codes
| Error Code | Meaning | Key Difference from 500121 |
|---|---|---|
| AADSTS50126 | Invalid credentials – wrong password | Password failed, MFA was not reached |
| AADSTS50076 | MFA required but not provided | User did not attempt MFA |
| AADSTS53003 | Conditional Access blocked sign-in | Policy block, not MFA failure |
| AADSTS50079 | MFA required for the first time | New MFA enrollment needed |
FAQs
What causes Microsoft Authenticator error 500121?
The most common cause is device clock drift invalidating TOTP codes. Other causes include: tapping “Not me” on an MFA prompt (which triggers an automatic account block), an expired Temporary Access Pass, a corrupted MFA secret in the Authenticator app, a recent email address or domain change causing a UPN mismatch, and Conditional Access policy restrictions based on device, location, or sign-in risk.
Is error 500121 a Microsoft server outage?
No, in the vast majority of cases it is not. It is a client-side or policy issue. Check status.office.com to rule out an outage, but expect to find the service is healthy.
Can error 500121 be fixed without reinstalling the Authenticator app?
Yes. Syncing device time (Fix 1) or unblocking the account in Entra ID (Fix 3) resolves the issue for most users without any reinstall.
Why does error 500121 keep coming back repeatedly?
Recurring 500121 usually means one of: ongoing clock drift (the phone time keeps slipping), an Authenticator app that is not updating automatically, or a Conditional Access policy that keeps blocking the same device or location.
Why won’t error 500121 go away even after resetting MFA?
If you reset authentication methods and issued a TAP but the error persists, the account is most likely still blocked by the Fraud Alert system from a previous “Not me” tap. You must explicitly unblock the user in Entra ID under Protection → Multifactor Authentication → Block/unblock users before the MFA reset will take effect.
How is error 500121 different from AADSTS50126?
AADSTS50126 means the password was wrong and authentication did not reach the MFA step. Error 500121 means the password was accepted but the MFA verification step then failed – the user received the prompt but the code or approval was rejected.
What should I do if I am completely locked out as the only admin?
Try signing in from a previously trusted device or network. If that fails, call Microsoft Support and ask specifically for the Data Protection Team. Have your error code, Request ID, Correlation ID, company name, billing details, and an alternate email ready. The Data Protection Team is the only team that can manually reset MFA for a sole admin account.
