Additional Microsoft Entra services and features related to identity, access, and network security
Because the Microsoft account is the only Global Administrator on the old Microsoft Entra tenant and multifactor authentication (MFA) cannot be completed, self-service deletion is blocked. Deleting the tenant is a prerequisite for closing the account, and only a Global Administrator can delete the organization.
In this situation, the supported path is to involve Microsoft support/Data Protection so they can verify identity and help regain access or adjust MFA so the tenant can be cleaned up and deleted.
Actionable steps:
- Prepare information
- Tenant name and domain (for example,
contoso.onmicrosoft.com). - The administrator username for the locked account.
- Any error messages seen when MFA fails.
- Tenant name and domain (for example,
- Contact Microsoft support / Data Protection team
- Use the appropriate Microsoft customer service phone number for the region (see “Customer service phone numbers - Microsoft Support”).
- When prompted by the automated system, clearly indicate the issue is with “Authenticator” and that this is an Office 365/Microsoft 365 for business or work/school account.
- Confirm that this is a company/work account, that it is the only Global Administrator, and that MFA is blocking access.
- Ask to open a service request and be routed to the Microsoft 365 Data Protection team to restore access to the tenant or reset MFA.
- (Optional) If direct support access is not available
- Create a new temporary Microsoft 365 trial tenant as described in the context.
- From that new tenant’s Microsoft 365 admin center, open a support ticket.
- In the ticket, state clearly that the problem is with a different, existing tenant where the only Global Administrator is locked out due to MFA and that the goal is to regain access in order to delete the old tenant and close the associated account.
- After Microsoft support restores access or resets MFA
- Sign in to the old tenant as Global Administrator.
- Prepare the tenant for deletion by ensuring:
- All outstanding invoices are paid.
- All users except the one Global Administrator are removed.
- All applications and service principals are removed.
- No multifactor authentication providers are linked.
- No active subscriptions (Microsoft 365, Azure, or Microsoft Entra ID P1/P2) remain.
- Then delete the organization from the Microsoft Entra admin center:
- Go to https://entra.microsoft.com and sign in as Global Administrator.
- Select Microsoft Entra ID.
- On the tenant’s Overview page, select Manage tenants.
- Select the checkbox for the old tenant and choose Delete.
- Resolve any checks that fail, then select Delete again to complete.
- Close the Microsoft business account
- After the Entra tenant is deleted and any Microsoft 365 subscriptions are fully ended, follow the “Close your Microsoft business account” process to close and delete the account and its associated tenant data.
Because MFA cannot be bypassed self-service and there is only one admin, Microsoft’s Data Protection team is required to break the deadlock so the tenant can be deleted and the old account fully removed.
References:
- Delete a tenant in Microsoft Entra ID
- Close your Microsoft business account
- Overview: Remove a former employee and secure data
- Close your work or school account in an unmanaged Microsoft Entra organization
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- Error Code: 399287 - Microsoft Q&A