Skip to main content

Author: Jess

IT manager reviewing security settings for a Claude AI Microsoft 365 connector in a Manchester office

Claude AI M365 Connector: What Manchester Businesses Must Know Before Granting Access

Artificial intelligence is moving fast, and so is the way AI tools connect to your business systems. One integration attracting growing interest — and generating some genuine concern from security-conscious IT teams — is the Claude AI Microsoft 365 MCP connector.

If someone in your organisation is asking about connecting Claude AI to your Outlook, Teams, or SharePoint environment, this guide explains exactly what that means, what it can access, and what you need to have in place before you say yes.

This Is Not an Outlook Add-In

The first thing to understand is that the Claude AI M365 connector is not a simple Outlook plug-in. It is an Entra ID Enterprise Application — a cloud-to-cloud integration registered directly in your Microsoft Azure/Entra ID tenant.

That distinction matters enormously. An Outlook add-in only sees the email you currently have open. An Entra ID Enterprise Application, once consented to, can access data across your entire Microsoft 365 environment — every inbox, every calendar, every Teams message, every SharePoint file — based on the Microsoft Graph API permissions it has been granted.

This is the same architecture used by enterprise SaaS tools like Salesforce, DocuSign, and Zoom when they integrate with Microsoft 365. It is powerful and legitimate when properly managed. The risk arises when businesses do not understand what they have consented to.

How It Works: MCP and Microsoft Graph API

The connector uses the Model Context Protocol (MCP) — an open standard developed by Anthropic — to bridge Claude AI with your Microsoft 365 data. Think of MCP as a standardised interface that tells Claude what data sources are available and how to query them.

The data flow looks like this:

  • A user or administrator grants the Claude AI Enterprise Application consent in Entra ID
  • The application receives an OAuth 2.0 token scoped to the permissions it was granted
  • When Claude is asked to help with an email task, it queries the Microsoft Graph API using that token
  • Graph API returns live data from your Microsoft 365 tenant — full thread, attachments, calendar, contacts, Teams messages
  • That data is processed by Claude on Anthropic’s infrastructure and the response is returned

The critical word above is live. Claude is not processing a snippet of text that someone has copied in. It is making authenticated API calls to your Microsoft 365 environment and pulling real data in real time.

What Permissions It May Request

When an Entra ID Enterprise Application is registered, it requests specific Microsoft Graph API permission scopes. Depending on the connector’s configuration, these can include:

  • Mail.Read / Mail.ReadWrite — full read access to every email in the authorised mailbox, every folder, every attachment
  • Calendars.Read / Calendars.ReadWrite — all calendar events, attendee lists, meeting content, and private appointments
  • Contacts.Read — every contact in the address book including names, numbers, emails, and notes
  • Files.Read / Files.ReadWrite — OneDrive files, shared documents, and linked content
  • Chat.Read / ChannelMessage.Read — private Teams chats and channel messages
  • Sites.Read — SharePoint document libraries accessible to the user

If an administrator grants tenant-wide admin consent rather than per-user consent, these permissions apply to every user in the organisation — not just the individual who installed the connector. A single consent click can grant Claude AI read access to your entire company’s data.

Important: Unlike an Outlook add-in — which stops working when you close Outlook — an Entra ID Enterprise Application maintains persistent OAuth tokens. Claude’s access to your M365 data continues in the background even when no one is actively using it.

The Account Tier Problem

How Anthropic handles the data it receives depends entirely on which Claude account type is used when the connector is authorised. This is the detail that most businesses miss.

  • Free and Pro personal accounts (claude.ai) — conversations and processed data may be used to help improve Anthropic’s AI models. The free account has this enabled by default.
  • Claude for Work — data is not used for model training by default, and organisational admin controls are available.
  • Claude Enterprise — data is never used for training, with full admin controls and audit capability.

If a member of staff — or an IT administrator — connects the M365 MCP connector using a personal Claude Pro account, everything Claude accesses via the Microsoft Graph API could be used to improve Anthropic’s models. Your client correspondence, your HR discussions, your financial emails, your Teams conversations: all processed through a personal account with no organisational controls and no ability to request deletion.

UK GDPR Obligations

Your organisation is the data controller for the personal data stored in your Microsoft 365 environment. When an Entra ID Enterprise Application grants an AI system access to that data, you carry full GDPR responsibility for what happens to it.

Unless you have:

  • A formal data processing agreement (DPA) with Anthropic
  • A business-tier Claude account (Claude for Work or Claude Enterprise)
  • Completed a Data Protection Impact Assessment (DPIA) under Article 35
  • Reviewed and minimised the Graph API permissions granted

…then connecting your Microsoft 365 tenant to Claude AI via the MCP connector is almost certainly non-compliant with UK GDPR. The ICO’s enforcement focus on AI-related data processing is growing, and unmanaged AI connectors with tenant-wide access represent exactly the kind of scenario they are scrutinising.

Fines for serious infringements can reach £17.5 million or 4% of global annual turnover — whichever is higher.

What to Do Before Granting Access

If someone in your organisation is requesting this integration — or if you suspect it may already be active — here are the immediate steps:

1. Audit Your Entra ID Enterprise Applications

Go to the Microsoft Entra admin centre (entra.microsoft.com), navigate to Enterprise Applications, and review what is registered in your tenant. Look for any Claude AI or MCP-related applications and check the permissions that have been consented to.

2. Restrict User Consent Policies

By default in many Entra ID configurations, standard users can consent to applications requesting permissions marked as “low risk.” This is a dangerous default. Set your user consent policy to require admin approval for all third-party application consent requests.

3. Check for Existing Admin Consent Grants

In the Entra admin centre under Enterprise Applications > Permissions, review any existing admin consent grants. Revoke any you did not deliberately authorise.

4. Establish an AI Tool Policy

Before any AI-to-M365 integration goes live, you need a written policy that defines: which AI tools are approved, what account tier is required, what Graph API permissions are acceptable, and who has authority to authorise new integrations.

5. Use Only Business-Tier Claude Accounts

If you proceed with the integration, it must be authorised using a Claude for Work or Claude Enterprise account. Personal accounts — even paid Pro accounts — must never be used to authorise access to company data.

6. Apply Least Privilege to Graph API Permissions

Request only the permissions actually needed. Read-only where possible. Avoid tenant-wide application permissions unless there is a specific, documented business requirement.

How Pro Business Can Help

We work with businesses across Manchester and the North West to navigate exactly these decisions: emerging AI tools that offer genuine productivity value, but need to be deployed correctly to stay safe and compliant.

Our AI and M365 security services include:

  • Entra ID Enterprise Application audit — reviewing all registered applications and consent grants in your tenant to identify any unauthorised or high-risk AI connectors
  • Graph API permission review and remediation — assessing what your M365 data is exposed to and recommending the minimum necessary permissions
  • AI usage policy development — clear, enforceable policies for which AI tools staff can use, with what data, and under what conditions
  • DPIA support — completing the Data Protection Impact Assessments required under UK GDPR before AI tools process personal data
  • User consent controls — implementing Entra ID policies to prevent staff from independently granting third-party apps access to company data
  • Staff training — ensuring your team — including IT administrators — understands what granting Enterprise Application consent actually means

The question is not whether AI tools like Claude belong in your business. Many of them are genuinely useful. The question is whether the integration has been done properly — with the right account tier, the right permissions, the right agreements, and the right controls.

If you are not sure, let us check. Contact the Pro Business team for a no-obligation Entra ID and AI connector audit.

Frequently Asked Questions

What is the Claude AI M365 MCP connector?

It is a cloud-to-cloud integration that connects Claude AI (made by Anthropic) to your Microsoft 365 environment via an Entra ID Enterprise Application. It uses the Model Context Protocol (MCP) and Microsoft Graph API to give Claude access to your emails, calendars, files, and Teams messages in real time. It is not an Outlook add-in — it is a tenant-level integration with persistent access.

Can my staff install this without IT knowing?

Potentially, yes — depending on your Entra ID user consent settings. If your tenant allows users to consent to low-privilege application permissions, a staff member could authorise the connector using their own Claude account without IT or admin approval. This is why reviewing and restricting your user consent policy is one of the first recommended steps.

Is it GDPR-compliant to use this connector?

Not without the right setup. You need a formal data processing agreement with Anthropic, a Claude for Work or Enterprise account (not a personal account), a completed DPIA, and properly scoped Graph API permissions. Using a personal Claude account to authorise M365 access is almost certainly non-compliant with UK GDPR.

What is the difference between a personal Claude account and Claude for Work?

Personal Claude accounts (Free and Pro on claude.ai) may use conversation data to improve Anthropic’s AI models, offer limited data retention controls, and provide no admin oversight. Claude for Work and Claude Enterprise do not use data for training by default, offer organisational admin controls, and support proper data governance — making them the only acceptable account types for business use.

How do I check whether the connector is already active in my tenant?

Log in to the Microsoft Entra admin centre (entra.microsoft.com), navigate to Enterprise Applications, and search for Claude or Anthropic. Review the permissions tab of any results to see what Graph API scopes have been consented to. Pro Business can carry out this audit for you as part of an Entra ID security review.

Does this connector keep working when staff are not actively using it?

Yes. Unlike an Outlook add-in that only operates when open, an Entra ID Enterprise Application holds persistent OAuth tokens. Unless access is explicitly revoked in Entra ID, the connector retains the ability to query your Microsoft 365 data continuously — even when no one is logged into Claude.

Can Pro Business help us deploy this safely if we want to use it?

Yes. We can help you assess whether the integration is right for your business, select the appropriate Claude account tier, configure the minimum necessary Graph API permissions, complete a DPIA, and implement Entra ID controls to manage ongoing access. Contact our team to discuss a compliant deployment.

ChatGPT Outlook Add-In Risks: What Every Business Needs to Know Before Installing It

Updated August 2026: Essential guidance for UK businesses using or considering the ChatGPT Outlook add-in

The ChatGPT Outlook add-in is one of the fastest-adopted AI tools in UK workplaces right now. It promises to help employees draft emails faster, summarise long threads, and manage their inboxes more efficiently. For busy teams handling high volumes of correspondence, the appeal is obvious.

But here is the problem: most businesses that have staff using it have no idea what data it is accessing, where that data goes, or whether it complies with UK GDPR. This guide sets out what every UK business owner and IT decision-maker needs to understand before this tool goes any further in your organisation.

What Does the ChatGPT Outlook Add-In Actually Do?

The ChatGPT Outlook add-in integrates OpenAI’s large language model directly into Microsoft Outlook. Once installed, it can read email content, suggest replies, summarise conversations, and assist with drafting. It operates within the Outlook interface, which means it runs with whatever permissions the user has granted.

Employees typically install it because it genuinely saves time. AI-assisted email is useful. The issue is not the functionality — it is the data implications of that functionality, and whether your business has properly assessed them before deployment.

What Data Can It Access?

⚠️ Important: The ChatGPT Outlook add-in can access substantially more than just the email you are currently drafting. When granted full permissions, it can read incoming and outgoing email content (including historical messages), attachments and files within those emails, calendar data and meeting details, contact information and distribution lists, and any documents uploaded or shared via connected Microsoft 365 services. In practice, this means a single staff member installing the add-in could expose client correspondence, internal financial discussions, HR communications, and strategic documents to an external AI service — without your knowledge or explicit sign-off.

This is not a hypothetical risk. The permissions are real, the data transfer happens in real time, and the implications for your business depend entirely on which account type your employees are using.

The Critical Distinction: Personal vs Business/Enterprise Accounts

This is the most important thing to understand, and it is the point that most IT teams miss. The data handling rules for ChatGPT differ significantly depending on whether your staff are using a personal OpenAI account or a Business/Enterprise subscription.

“By default, we may use content you provide us to train our models. You can opt out of model training at any time from your account settings. If you use the API or are on a ChatGPT Enterprise or Team plan, we do not train on your content by default.”

— OpenAI Privacy Policy (August 2026)

What this means in practice: if your employees install the ChatGPT Outlook add-in using their personal OpenAI accounts (which the majority do, because it is free and quick to set up), the email content they process through it may be used to train OpenAI’s AI models — unless they have manually opted out. Most users have not opted out, because they do not know the setting exists.

If your business has a ChatGPT Team or Enterprise subscription, training on your data is off by default. But if individual employees are using free personal accounts — as is extremely common — you have no such protection, and you almost certainly have no data processing agreement in place with OpenAI either.

Four Key Risks Every Business Must Address

1. Uncontrolled Personal Account Use by Employees

The most common scenario we see is employees installing the add-in on their own initiative using personal free accounts. They do this because it is useful, not because they intend to cause harm. But from a data governance perspective, this represents unmanaged data egress. Your business data is leaving your controlled environment and being processed by a third-party service under terms you have not reviewed and did not agree to on behalf of your organisation.

2. UK GDPR Data Processing Obligations

Under UK GDPR, your business is a data controller. When you use a third-party service to process personal data — including client emails, employee details, or any personally identifiable information — that third party becomes a data processor. You are legally required to have a Data Processing Agreement (DPA) in place with them, and you must ensure their security measures are adequate.

If employees are using personal ChatGPT accounts to process business data, you almost certainly have no DPA with OpenAI. If OpenAI processes or stores that data in the US (which it does), you need to ensure the transfer meets UK international data transfer requirements under the UK GDPR framework. Most businesses using the add-in informally have not addressed any of this.

3. AI Model Training Using Company Data

As OpenAI’s own policy confirms, personal account data may be used for training. This means confidential client correspondence, business strategy discussions, financial information, and sensitive HR communications could, in theory, become part of the data used to improve OpenAI’s models. Even if specific data is anonymised during training, the fact that it has been transmitted to and processed by an external service is itself a compliance issue under UK GDPR.

4. Shadow AI and Unmanaged Usage

Perhaps the greatest long-term risk is not any single incident but the broader pattern of shadow AI adoption. When employees discover useful tools independently and use them without IT or compliance oversight, you lose visibility into where your data is going. Shadow AI is the AI equivalent of shadow IT — and it is growing rapidly in UK workplaces. Without a clear policy and technical controls, the ChatGPT Outlook add-in is just the start.

High-Risk Data Categories to Watch

🔴 Client & Customer Data

  • Client email correspondence
  • Case details and personal information
  • Contract and agreement content
  • Complaint and dispute records

🔵 Financial & Commercial Data

  • Invoice and payment discussions
  • Pricing and margin information
  • Budget and forecast data
  • Bank and account references

🟡 HR & People Data

  • Employee personal details
  • Salary and benefits correspondence
  • Performance and disciplinary records
  • Recruitment communications

🟢 Internal & Strategic Data

  • Business strategy discussions
  • Supplier and partner negotiations
  • M&A and investment conversations
  • Intellectual property and trade secrets

Any of these categories passing through a personal ChatGPT account represents a data breach risk, a UK GDPR compliance failure, or both.

Pre-Deployment Checklist: Before You Allow the Add-In

If you are considering officially deploying the ChatGPT Outlook add-in — or if you want to get control of employees who are already using it — work through the following checklist.

Action Required Details Priority
Audit current usage Identify which staff are already using the add-in and which account type (personal vs Enterprise) Critical
Review OpenAI’s DPA Obtain and review OpenAI’s Data Processing Agreement; ensure it covers your use case Critical
Disable personal account use Use Microsoft Intune or Group Policy to restrict add-in installation to approved accounts only Critical
Upgrade to ChatGPT Team/Enterprise Enterprise plan disables model training on your data by default and includes a DPA High
Update privacy policy and ROPA Add AI tool usage to your Record of Processing Activities; update client-facing privacy notices High
Conduct a DPIA Data Protection Impact Assessment required if processing special category or high-risk data with AI High
Train staff on AI data risks Ensure all employees understand what they can and cannot process through AI tools Medium
Publish an AI usage policy Document approved AI tools, permitted use cases, and prohibited data types Medium

How Pro Business Helps

The ChatGPT Outlook add-in is a genuine productivity tool — but only when deployed correctly, with the right controls in place. The problem is that most businesses do not have the internal expertise to assess the data protection implications, configure Microsoft 365 correctly to restrict personal account use, or draft the policies required to remain UK GDPR compliant.

Pro Business works with UK businesses to make AI adoption safe and compliant. Our security solutions include AI readiness assessments, Microsoft 365 configuration reviews, UK GDPR compliance support, and staff training on AI data risks. We help you get the productivity benefits of tools like ChatGPT without the legal and reputational exposure that comes from unmanaged adoption.

We can audit your current Microsoft 365 environment, identify whether the ChatGPT add-in is already in use across your organisation, assess your data protection obligations, and implement the technical controls needed to protect your business — all without disrupting the tools your staff are already using.

If you are not sure whether your business is exposed right now, that uncertainty is itself a risk. Get in touch for a straightforward conversation about where you stand.

Is Your Business Exposed Right Now?

If you have staff using the ChatGPT Outlook add-in — or any AI tool — without a formal policy or data processing agreement in place, you may already be in breach of UK GDPR. We can assess your risk and implement the controls needed to protect your business.

Call: 0161 519 0764 | Email: info@pro-business.co.uk

View Our Security Solutions →


Related reading: If your business is using Microsoft Copilot, the data access and compliance questions are similar — and in some respects more significant given Copilot’s deeper Microsoft 365 integration. Read our guide: Microsoft Copilot: What Every UK Business Owner Needs to Know Before You Switch It On.

Microsoft Authenticator: The Complete Guide for Business Users

Passwords alone are no longer enough. With phishing attacks, credential stuffing and brute force attempts hitting businesses every day, relying on a password is a bit like locking your front door but leaving the window wide open.

That is where multi-factor authentication (MFA) comes in. And Microsoft Authenticator is one of the simplest, most reliable ways to get it set up across your organisation.

This guide covers everything business users need to know: what it is, how it works, how to use it day to day, what to do when things go wrong, and how to stay safe from a growing threat called MFA fatigue.

What Is Microsoft Authenticator?

Microsoft Authenticator is a free app for iOS and Android that adds a second layer of security to your Microsoft 365 account (and many other services). When you log in, you are not just asked for your password. You also have to prove it is really you by approving a notification or entering a short code from the app.

That second step is what makes it so effective. Even if someone gets hold of your password, they still cannot get into your account without your phone.

The numbers are stark: Microsoft’s own research shows that enabling MFA blocks more than 99.9% of automated account compromise attacks. For any business using Microsoft 365, enabling it is not optional. It is essential.

How Microsoft Authenticator Works

There are two main ways the app proves your identity:

  • Push notifications: When you sign in, a notification pops up on your phone. It shows you the app you are signing into, your location and a two-digit number that matches what is shown on your screen. Tap Approve and you are in.
  • One-time codes (TOTP): The app generates a six-digit code that refreshes every 30 seconds. You type this code into the sign-in screen. Useful when you do not have mobile data or if push notifications are unavailable.

Both methods are far more secure than SMS codes, which can be intercepted. The Authenticator app works offline and is tied to your specific device, making it much harder to spoof.

Setting It Up

Getting started takes about five minutes. The short version:

  • Download the Microsoft Authenticator app from the App Store or Google Play
  • Sign into your Microsoft 365 account at mysignins.microsoft.com/security-info
  • Add a sign-in method and select Authenticator app
  • Scan the QR code shown on screen
  • Approve a test notification to confirm everything is working

For a full walkthrough with screenshots, see our step-by-step setup guide.

If you are rolling MFA out across a team, your IT admin can enforce it through Azure Active Directory Conditional Access policies, so users are prompted to set it up automatically on their next sign-in.

Using It Day to Day

Once it is set up, Microsoft Authenticator mostly stays out of the way. You will typically only see it when signing into a new device, after a period of inactivity, or when accessing something sensitive.

Here is what a normal sign-in looks like:

  • Enter your email and password as usual
  • A notification appears on your phone
  • Check the two-digit number matches what is on your screen
  • Tap Approve
  • Done. You are in.

The whole thing takes about five seconds. Once you get used to it, it becomes second nature.

Managing Authenticator: New Phone and Backup Methods

The biggest gotcha with any authenticator app is: what happens when you get a new phone, lose your device, or it breaks?

The good news is Microsoft has thought about this.

  • Cloud backup: Enable the backup option in the app settings. On Android this uses your Google account; on iOS it uses iCloud. If you get a new phone, you can restore your accounts during setup.
  • Add a backup sign-in method: Go to mysignins.microsoft.com/security-info and add a secondary method, such as a backup phone number or email. This gives you a fallback if you cannot access the app.
  • Temporary access pass: If your IT admin has enabled it, they can generate a short-term passcode that lets you sign in and re-register your new device without needing the old phone.

The biggest mistake people make is waiting until they are locked out to think about this. Set up your backup methods now, while you still have access.

Common Issues and How to Fix Them

  • Notification did not arrive: Check your phone is connected to the internet and that notifications are enabled for the app. You can also use the one-time code as a fallback.
  • Code says it is invalid: Make sure your phone’s clock is set to automatic time sync. TOTP codes are time-sensitive and drift of even 30 seconds can cause failures.
  • App is not showing accounts: If you reinstalled the app without restoring from backup, you may need to re-add your accounts. Contact your IT admin if you are unable to sign in.
  • Locked out completely: Your IT admin can reset your MFA registration in the Azure portal, or issue a Temporary Access Pass to get you back in.

MFA Fatigue: A Real and Growing Risk

There is one attack you need to know about: MFA fatigue, sometimes called MFA prompt bombing.

Here is how it works. An attacker has already obtained your password (perhaps from a data breach or phishing). They then attempt to sign in repeatedly, sending a flood of approval notifications to your phone. The hope is that you will eventually tap Approve out of frustration or confusion.

Several high-profile breaches have happened this way.

How to protect yourself:

  • Never approve a notification you did not initiate. If a request appears and you are not actively signing in, deny it immediately.
  • Check the number match. Microsoft now shows a two-digit code that must match between the app and the sign-in screen. This means you cannot accidentally approve a request from an attacker.
  • Report unexpected requests. If you start receiving repeated sign-in requests you did not trigger, tell your IT team straight away. It likely means your password has been compromised and needs changing.

Why Businesses in Manchester and Beyond Need This Now

Cyber attacks on small and medium businesses are increasing every year. Ransomware, business email compromise and account takeovers are not just problems for large corporations. They hit local businesses hard, often with no warning.

Enabling Microsoft Authenticator across your team is one of the most cost-effective security steps you can take. It costs nothing (the app is free), takes minutes to set up, and stops the vast majority of automated attacks in their tracks.

Need Help Rolling It Out?

If you would like support setting up MFA across your business, migrating to Microsoft 365, or reviewing your overall cyber security posture, the team at Pro Business are here to help.

Get in touch at support@pro-business.co.uk or give us a call. We work with businesses across Manchester and the North West, and we will get you sorted without the jargon.

How to Set Up Microsoft Authenticator: Step-by-Step Guide

If your IT team or Microsoft has prompted you to set up multi-factor authentication (MFA), this guide will walk you through the whole process in plain English. It takes about five minutes and you will only need your phone and a computer.

What You Will Need

  • Your smartphone (iPhone or Android)
  • A computer or laptop signed into your Microsoft 365 account
  • Your Microsoft 365 email address and password

Step 1: Download the Microsoft Authenticator App

On your phone, open the App Store (iPhone) or Google Play Store (Android) and search for Microsoft Authenticator. It is free and published by Microsoft Corporation. Download and install it.

Once installed, open the app. You will be shown a welcome screen. You do not need to do anything in the app just yet.

Step 2: Go to Your Microsoft Security Settings

On your computer, open a browser and go to:

mysignins.microsoft.com/security-info

Sign in with your work Microsoft 365 account if prompted. You will see a page called Security info showing your current sign-in methods.

Step 3: Add the Authenticator App

  • Click Add sign-in method
  • From the dropdown, choose Authenticator app
  • Click Add
  • Click Next on the screen that explains what the Authenticator app does
  • On the next screen, click Next again. Microsoft will now show you a QR code on your screen.

Step 4: Scan the QR Code

Now switch to your phone:

  • In the Microsoft Authenticator app, tap the + button (top right on iPhone, or the add icon on Android)
  • Choose Work or school account
  • Choose Scan a QR code
  • Point your phone camera at the QR code on your computer screen

The app will scan it automatically and add your account. You will see your name and email address appear in the app.

Step 5: Allow Notifications

When prompted on your phone, allow the Microsoft Authenticator app to send you notifications. This is how it will notify you when you need to approve a sign-in. Without notifications enabled, the app will not be able to send you approval prompts.

On iPhone: tap Allow when iOS asks about notifications.

On Android: tap Allow when prompted.

Step 6: Approve the Test Notification

Back on your computer, click Next. Microsoft will send a test notification to your phone to confirm everything is working.

  • A notification will appear on your phone
  • It will show a two-digit number. Check that number matches what is shown on your computer screen
  • Tap Yes or Approve on your phone

Your computer will confirm that the app is set up. Click Next and then Done. That is it. You are set up.

Using Microsoft Authenticator Day to Day

Once it is configured, here is what happens each time you sign in:

  • Enter your email and password as normal
  • A notification appears on your phone with a two-digit number
  • Check the number matches what is on your screen
  • Tap Approve
  • You are signed in

If you do not have mobile data or the notification does not arrive, open the Authenticator app and use the six-digit code shown under your account. Type that code into the sign-in screen instead. The code refreshes every 30 seconds.

Getting a New Phone

Before you get a new phone, do two things:

  • Enable cloud backup in the Authenticator app settings (Google account on Android, iCloud on iPhone)
  • Add a backup sign-in method at mysignins.microsoft.com/security-info, such as an alternative phone number

When you set up your new phone, install the Authenticator app and restore from your backup. Your accounts will be transferred. If you get stuck, your IT admin can reset your MFA registration so you can start fresh.

Need Help?

If you ran into any problems during setup, or if your business needs help rolling out MFA across the whole team, the Pro Business team are here for you.

Drop us an email at support@pro-business.co.uk and we will get you sorted. We support businesses across Manchester and the North West with Microsoft 365, cyber security and IT support.