A community member has associated this post with a similar question:
My organization has no Global Administrator

Only moderators can edit this content.

Orphaned Microsoft Entra tenant – no Global Administrator, need tenant admin recovery

David Collins 0 Reputation points
2026-03-07T12:09:12.7266667+00:00

I own and control the domain lockedingarage.com.au. A Microsoft Entra ID (Azure AD) tenant exists with Tenant ID: <PII EWMOVED> The tenant appears to have been auto-created, but there is no accessible Global Administrator. I cannot sign in to Entra or Microsoft 365 admin portals with my account. When attempting to access admin services, I receive: AADSTS16000 – User account from identity provider 'live.com' does not exist in tenant. Self-service password reset is not configured (SSPR_0011), and there is no administrator to enable it. I am able to prove domain ownership via DNS (TXT record). I need Microsoft to assign me as the first Global Administrator for this tenant using the standard tenant admin recovery process. No email (MX) changes are required. I have google workspace for domain hosting.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-03-07T12:09:27.1066667+00:00

    The tenant is an unmanaged or inaccessible Microsoft Entra ID directory that belongs to a domain controlled by the organization. To become the first Global Administrator and recover admin access, the standard path is:

    1. Verify that the tenant is associated with the owned domain
      • Confirm in the domain registrar that lockedingarage.com.au is registered and under control.
      • Check whether this domain is already verified in another Microsoft 365/Entra tenant. If the registrar shows the domain is paid for but not verified in the home tenant, it may be attached to an unmanaged directory.
      • For unmanaged directories created via self-service signup, a global admin can perform an admin takeover. See the guidance for internal admin takeover of unmanaged accounts created by self-service sign-up.
    2. Use the admin takeover / tenant recovery path
      • For unmanaged ("shadow") tenants created by self-service sign-up, perform an internal admin takeover. This process is designed specifically so an organizational owner of the domain can become the first admin:
        • Sign up to a Microsoft cloud service (for example, Power BI) using an account in the lockedingarage.com.au domain.
        • This launches the admin takeover wizard, which walks through proving control of the domain and then promotes the account to admin for that unmanaged tenant.
      • The takeover process relies on domain verification (typically via DNS records) to prove ownership of lockedingarage.com.au, which matches the requirement to prove domain ownership via TXT record.
    3. If the tenant is not simply unmanaged, or takeover fails, use Microsoft support / Data Protection team
      • When there is no accessible Global Administrator and self-service recovery (SSPR, MFA reset, etc.) is not available, Microsoft’s Data Protection team handles tenant admin recovery.
      • Open a support request specifically for tenant access recovery / admin lockout:
        • If access to any Microsoft 365 or Azure portal is available under another tenant, use that tenant to open a support ticket and clearly state that this is for admin recovery of a different tenant (provide the tenant ID 8310a254-1096-469a-bbc9-cd8484db7e0c and the domain lockedingarage.com.au).
        • If no portal access is available, call Microsoft using the global customer service phone numbers and request escalation to the Data Protection team for tenant admin recovery.
      • The Data Protection team can:
        • Reset credentials of an administrator account.
        • Help claim ownership of tenants that belong to the organization.
      • Be prepared to provide:
        • Proof of domain ownership (DNS TXT record, registrar information).
        • Business documentation tying the organization to lockedingarage.com.au.
    4. Understand what Microsoft for Nonprofits / other programs can and cannot do
      • All tenant ownership and access decisions are handled through Microsoft 365 support and the Data Protection process; program teams (such as Microsoft for Nonprofits) cannot bypass identity verification or directly assign Global Administrator.
      • They can assist with documentation and routing, but the actual assignment of a Global Administrator for the tenant is done only after identity verification through standard support channels.
    5. If the tenant is inaccessible due to inactivity
      • If the tenant has been blocked with error AADSTS5000225: This tenant has been blocked due to inactivity, the tenant administrator must contact Microsoft (via the global support phone numbers) within 20 days of the tenant entering the inactive state to request reactivation.
      • After 20 days in this state, the tenant is deleted and cannot be recovered.

    In summary, to be assigned as the first Global Administrator for the tenant:

    • First attempt an internal admin takeover of the unmanaged directory using a lockedingarage.com.au account and domain verification.
    • If that does not work or the tenant is not simply unmanaged, contact Microsoft support (phone or via another tenant) and request Data Protection / tenant admin recovery, providing tenant ID and proof of domain ownership so Microsoft can validate ownership and assign or reset a Global Administrator.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.