Tenant Admin Recovery

Rüdiger Jungbeck 0 Reputation points
2026-02-27T11:05:22.7+00:00

I have (several years ago) integrated a web app (https://lpsng.rsj.de) with "Login for Microsoft". This integration still works.

I also have (since many years) an Excel Addin (id:

Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Newest
  1. AI answer

    2026-02-27T11:05:44.1666667+00:00

    The add-in issue and the tenant admin issue are two separate problems.

    1. Identity API / Office.auth.getAccessToken error 13000

    The error message “Die Identitäts-API wird für dieses Add-In nicht unterstützt.” with code 13000 means the Identity API is not available for the add-in in the current environment. From the provided troubleshooting guidance for getAccessToken, the relevant points are:

    • The add-in must declare the Identity API requirement set in the manifest.
    • The platform where the add-in runs must support the Identity API.

    From the context:

    • Error 13012 is raised when the platform does not support getAccessToken (for example, some clients like iPad or specific Teams scenarios). In that case, the guidance is to fall back to an alternate auth method.
    • For 13007/“Unable to get an access token”, the guidance includes:
      • Ensure the add-in registration and manifest specify the profile permission (and openid if using MSAL.NET).
      • Ensure the app is enabled for users to sign in in the app registration’s Properties.

    Actionable checks for the add-in:

    1. Confirm the client supports the Identity API requirement set version declared in the manifest. If the host (Excel version / platform) does not support IdentityAPI 1.3, getAccessToken will not be available and the add-in must use a fallback sign-in flow.
    2. In the app registration for the web API used by the add-in:
      • Ensure the app is enabled for users to sign in (Azure portal → App registration → Managed application in local directory → Properties → “Enabled for users to sign-in?” = Yes).
      • Ensure the API exposes the correct scopes and that the add-in manifest’s <WebApplicationInfo> matches the registered app (App ID, resource, scopes).
    3. If getAccessToken continues to return an unsupported-API error on a supported client, treat this as a non‑supported scenario and keep the existing “Login with Microsoft” flow as a fallback, as recommended in the SSO troubleshooting guidance.
    4. Loss of admin access / wrong account type (error 53003) and regaining admin rights

    The tenant access problem is a classic “locked out of admin / wrong account type” scenario. The key points from the tenant access recovery and MFA lockout guidance are:

    • If the only global admin cannot sign in (for example, due to MFA or account type issues), Microsoft’s Data Protection team must verify identity and restore access.
    • Forum moderators and normal support channels cannot bypass identity verification or directly change tenant ownership.
    • Recovery is done through Microsoft 365 support, with identity verification based on business documentation, domain ownership, etc.

    Given that RSJ Software GmbH appears to have only one admin and that the current account cannot access Entra/Azure/M365 portals:

    1. Use Microsoft’s global customer service phone support
      • Call the regional number listed under “Customer service phone numbers - Microsoft Support”.
      • When the IVR asks about the problem, answer along the lines of:
        • Problem: “Authenticator” or “Sign-in / admin access”.
        • Product: “Office 365 for business” / “Azure / Microsoft 365 for business”.
        • Account type: “Company account”.
        • Are you an administrator? “Yes”.
        • Are there any other administrators? “No”.
      • Explicitly request a service request with the Data Protection team to restore access to the tenant where you are the only global admin.
      • Be prepared to provide:
        • The tenant’s primary domain (e.g., …onmicrosoft.com or your custom domain).
        • The admin UPN/email used previously.
        • Business documentation proving RSJ Software GmbH ownership and domain control.
    2. If direct phone routing fails, create a temporary trial tenant to open a ticket
      • Sign up for a Microsoft 365 trial (business/enterprise) to create a new, separate tenant.
      • In the new tenant’s Microsoft 365 admin center, go to Support → Help & support.
      • Open a support ticket clearly stating:
        • You are locked out of a different, existing tenant where you are the only global admin.
        • Provide the locked tenant’s domain and admin account.
        • Request escalation to the Data Protection team for admin/MFA reset and tenant access recovery.
      • This trial tenant is only a channel to contact support; it does not give access to the old tenant’s data.
    3. General constraints
    • Microsoft for Nonprofits and general Microsoft 365 support cannot bypass identity verification or directly grant admin rights without the Data Protection process.
    • All tenant ownership and access decisions are handled through Microsoft 365 support and the Data Protection team.

    In summary:

    • For the add-in, verify platform support for IdentityAPI and ensure the app registration is correctly configured; if the host does not support IdentityAPI, keep using the existing sign-in flow as fallback.
    • For regaining admin privileges, use Microsoft’s phone support or a temporary trial tenant to open a ticket with the Data Protection team, who can verify identity and restore global admin access to the RSJ Software GmbH tenant.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.