Skip to main content

MFA Prompt Loop in Microsoft 365 — How to Fix

Fix the MFA prompt loop where Microsoft 365 keeps asking for multi-factor authentication repeatedly without granting access. Covers token issues, Conditional Access conflicts, and browser problems.

6 min readUpdated March 29, 2026

Overviewsection

The MFA prompt loop is one of the most frustrating Microsoft 365 issues: you enter your password, complete MFA, and then get sent straight back to the MFA prompt — endlessly. This can affect Outlook, Teams, SharePoint, or any Microsoft 365 app.

This is almost always caused by one of five things: stale tokens, browser state, Conditional Access conflicts, device compliance failures, or a misconfigured MFA registration.

Fix 1: Clear Browser State (Most Common)section

Stale cookies and cached tokens are the #1 cause.

For Edge / Chromesection

  1. Press Ctrl + Shift + Delete
  2. Set time range to All time
  3. Check: Cookies and other site data, Cached images and files
  4. Click Clear data
  5. Close and reopen the browser
  6. Sign in again

For a faster targeted clearsection

Clear only Microsoft-related cookies:

  1. Go to edge://settings/siteData (Edge) or chrome://settings/cookies/all (Chrome)
  2. Search for microsoft and live.com
  3. Delete all matching entries
  4. Restart the browser

Try InPrivate / Incognitosection

Open an InPrivate window (Ctrl + Shift + N in Edge) and try signing in. If it works in InPrivate but not in a normal window, the problem is definitely cached browser state.

Fix 2: Revoke User Sessionssection

If the user's authentication tokens are corrupted or stuck in a bad state, revoke all sessions to force a clean re-authentication.

From the admin portalsection

  1. Go to entra.microsoft.com > Users > find the user
  2. Click Revoke sessions
  3. Ask the user to close all apps and sign in again

From PowerShellsection

powershell
Connect-MgGraph -Scopes "User.ReadWrite.All"
Revoke-MgUserSignInSession -UserId "user@company.com"

The user will need to re-authenticate on all devices after this.

Fix 3: Check Conditional Access Policiessection

Conflicting Conditional Access policies are a common cause of MFA loops. The loop happens when one policy grants access after MFA, but another policy blocks the session, triggering a new sign-in that asks for MFA again.

Diagnose with sign-in logssection

  1. Go to entra.microsoft.com > Monitoring > Sign-in logs
  2. Find the affected user's recent sign-in attempts
  3. Click a sign-in entry > Conditional Access tab
  4. Look for policies showing Failure — these are causing the block

Diagnose with the What-If toolsection

  1. Go to entra.microsoft.com > Protection > Conditional Access > What If
  2. Select the affected user and the application they are trying to access
  3. Review which policies would apply and whether any conflict

Common conflictssection

Policy APolicy BResult
Require MFARequire compliant device (device not compliant)MFA loop — MFA passes but compliance blocks, triggering re-auth
Require MFA from all locationsBlock access from untrusted locationsLoop if the user's location is classified as untrusted
Require MFA for all appsExclude a specific appLoop if the app was incorrectly identified
Tip

The most common conflict is a device compliance policy blocking access after MFA succeeds. Check if the user's device is marked as compliant in Intune (intune.microsoft.com > Devices > search for the device).

Fix 4: Re-register MFA Methodssection

If the user's MFA registration is corrupt or their Authenticator app is out of sync:

Have the user re-registersection

  1. Go to mysignins.microsoft.com/security-info
  2. Delete the existing Authenticator entry
  3. Click Add sign-in method > Authenticator app
  4. Set up the Authenticator app fresh with a new QR code scan

Admin-initiated resetsection

If the user cannot access the portal:

powershell
# Remove all authentication methods for the user
# Then have them re-register at next sign-in
Connect-MgGraph -Scopes "UserAuthenticationMethod.ReadWrite.All"

# List current methods
Get-MgUserAuthenticationMethod -UserId "user@company.com"

# Delete a specific method (e.g., phone)
Remove-MgUserAuthenticationPhoneMethod -UserId "user@company.com" -PhoneAuthenticationMethodId "<method-id>"

Or from the admin portal:

  1. Go to entra.microsoft.com > Users > find the user
  2. Click Authentication methods
  3. Click Require re-register MFA

Fix 5: Check for Token Lifetime Issuessection

If the user is on a managed device and the MFA loop happens specifically in desktop apps (Outlook, Teams):

Clear Office credential cachesection

  1. Close all Office apps
  2. Open Credential Manager (search in Start)
  3. Under Windows Credentials and Generic Credentials, remove all entries containing:
    • MicrosoftOffice16
    • msteams
    • login.microsoftonline.com
  4. Reopen the Office app and sign in again

Clear Teams-specific cachesection

  1. Close Teams completely (check system tray)
  2. Press Win + R, type %appdata%\Microsoft\Teams
  3. Delete the contents of the folder
  4. Restart Teams

Clear the WAM token brokersection

The Web Account Manager (WAM) handles authentication for Office apps on Windows:

powershell
# Run in an elevated PowerShell
dsregcmd /forcerecovery

Then restart the machine and sign in again.

Fix 6: Check for Hybrid Join Issuessection

If the device is Microsoft Entra hybrid joined and the MFA loop only happens on this specific device:

powershell
# Check device registration status
dsregcmd /status

Look for:

  • AzureAdJoined: YES
  • DomainJoined: YES (for hybrid)
  • DeviceAuthStatus: SUCCESS

If any of these are wrong:

powershell
# Leave and rejoin
dsregcmd /leave
# Restart the device
# It will automatically rejoin via Group Policy

Diagnostic Flowchartsection

SymptomFirst Step
Loop in browser onlyClear cookies and cache (Fix 1)
Loop in all apps and browsersRevoke sessions (Fix 2)
Loop on one device, works on othersClear credential cache (Fix 5) or check device registration (Fix 6)
Loop for one user, others are fineRe-register MFA (Fix 4) or check CA policies for that user (Fix 3)
Loop for all usersCheck Conditional Access for a recent policy change (Fix 3)

When to Escalatesection

Open a support case via admin.microsoft.com > Support > New service request if:

  • The MFA loop persists after trying all fixes above
  • Sign-in logs show no Conditional Access failures but the loop continues
  • The issue started after a Microsoft service update (may be a platform-side issue)
  • The user's account shows unusual sign-in activity suggesting compromise

Need help reviewing your sign-in setup?section

For help diagnosing an MFA loop, explore on-demand remote IT support. For ongoing Microsoft 365 administration across your team, see managed IT support.

MFAMicrosoft 365TroubleshootingMicrosoft Entra IDConditional Access

Was this article helpful?