What the verification methods page does
The page at https://aka.ms/mfasetup shows you every phone number, email address, and authentication app Microsoft has on file for your account. This is where you add new ways to prove you are who you say you are when you sign in, and where you remove old ones that no longer work. If you have lost access to a phone or changed your email, this page is where you fix it before you get locked out.
Microsoft uses this list when you sign in from a new device, when your password fails, or when the system detects something unusual about your login. The more current methods you have here, the faster you can get back in if something goes wrong. If your only phone number is one you no longer own, or your only email is one you cannot reach, you are one lost device away from being unable to recover your account.
Key Takeaways
- Visit https://aka.ms/mfasetup while you are signed in to see every phone number, email, and app Microsoft has registered to your account.
- Remove any phone numbers or email addresses you no longer use or no longer have access to, because Microsoft may send recovery codes to them.
- Add at least one phone number and one email address that you actually check regularly, so you can receive recovery codes if you get locked out.
- If you use an authenticator app like Microsoft Authenticator, test it once a month to make sure it still works and that you have your backup codes written down.
- Check this page every time you change your phone number, get a new email address, or stop using a device where you were signed in.
How to reach the verification methods page
Open a web browser and go to https://aka.ms/mfasetup. You must already be signed in to your Microsoft account — if you are not, the page will ask you to sign in first. If you have trouble reaching the page, you can also go to account.microsoft.com, select Security from the left menu, then choose Advanced security options, and look for the section labeled Additional security info.
The page works the same way on a phone browser, a tablet, or a desktop computer. You do not need to read anything or use a special app to view or change your methods. If you are signed in on a shared computer, sign out completely when you are done, because this page shows sensitive recovery information.
What to remove from your verification methods
Look through the list and delete any phone number you no longer own. If you upgraded your phone and your old number went to someone else, that old number is now a security risk — Microsoft might send a recovery code to it, and the new owner could intercept it. The same applies to any email address you no longer have access to. If you closed a work email account or abandoned a Gmail address, remove it from this list.
You should also remove any authentication app you no longer use. If you switched phones and set up Microsoft Authenticator on your new phone but never deleted it from your old phone, remove the old one. To delete a method, find it in the list, click or tap the three dots next to it, and select Delete. Microsoft will ask you to confirm — this is intentional, to prevent accidental removal.
What to add to your verification methods
You need at least two ways to prove you are you. The safest combination is a phone number you use every day plus an email address you check regularly. When you add a phone number, Microsoft will send a text message to confirm it works — you will see a code on your screen and receive it by text, and you enter the code to prove you own that number. When you add an email, Microsoft sends a link you click to confirm.
To add a new method, look for the button labeled Add a sign-in method or Add security info. Choose whether you want to add a phone number, email, or authenticator app. If you choose a phone number, select whether you want to receive codes by text or voice call — text is faster, but voice call works if your phone cannot receive texts. Follow the prompts to enter the number or email and confirm it works.
Setting up an authenticator app as a backup
An authenticator app like Microsoft Authenticator generates a code that changes every 30 seconds. This is stronger than text messages because the code only exists on your phone — no one can intercept it in transit. If you set one up, write down the backup codes Microsoft gives you and store them somewhere safe, like a locked drawer or a password manager. These codes let you sign in if you lose your phone.
To add an authenticator app, select Add a sign-in method and choose Authenticator app. Microsoft will show you a QR code. Open Microsoft Authenticator on your phone, tap the plus sign, choose Work or school account, and scan the QR code. The app will show a number — enter that number on the website to confirm it is working. Then take a screenshot of the backup codes or write them down by hand, and keep them somewhere you will remember.
What to do if you cannot reach the page
If you are signed in but the page will not load, try clearing your browser cache and cookies, then visit the link again. If you are not signed in and cannot sign in because you have forgotten your password, you will need to use a recovery method you set up earlier — this is why having current methods on file matters. Go to account.microsoft.com and select Can't access your account, then follow the steps to recover your account using a phone number or backup email.
If you have lost access to all your recovery methods, contact Microsoft Support through the account recovery page. They can verify your identity by asking security questions or other means, but this process takes longer than using a recovery method you set up in advance. This is the situation the verification methods page is designed to prevent.
How often to check your verification methods
Check this page at least once every six months, or whenever you make a major change to your phone or email. If you get a new phone, add it to your verification methods before you sell or recycle the old one. If you change your phone number, remove the old one when ready. If you stop using an email address, remove it. The goal is to make sure that every method on this page is one you can actually use right now.
If you use an authenticator app, test it once a month by signing out of your Microsoft account on one device and signing back in using the app code. This confirms the app still works and that you know where your backup codes are. A verification method that does not work is worse than no method at all, because you might rely on it in an emergency and find it has stopped working.
Frequently Asked Questions
What happens if I remove all my verification methods?
Microsoft will not let you remove your last method. You must have at least one way to prove you are you. If you try to delete your only phone number or email, the system will show an error and ask you to add a new method first.
Can someone else see my verification methods if they know my password?
No. Even if someone has your password, they cannot see your verification methods page or change them without also passing a verification check — Microsoft will send a code to one of your registered methods and ask you to enter it. This is why keeping your methods current is so important.
Do I need to use Microsoft Authenticator, or can I use a different app?
Microsoft Authenticator is the strongest option because it is made by Microsoft and works seamlessly with your account. Other authenticator apps like Google Authenticator or Authy will not work with Microsoft accounts — you must use an app Microsoft supports, or stick with phone numbers and email addresses.
What if I get a new phone and forget to add it to my verification methods?
If you set up your new phone with your Microsoft account, you can sign in and add it to your verification methods right away. If you have not signed in yet, use one of your existing methods — a phone number or email — to receive a recovery code and sign in on the new phone.
How long does it take Microsoft to send a recovery code?
Text messages usually arrive within seconds. Email can take a few minutes. If you do not receive a code within 10 minutes, check that the phone number or email on file is correct by visiting the verification methods page, and try requesting the code again.