A cloud-based identity and access management service for securing user authentication and resource access
The tenant is an unmanaged or inaccessible Microsoft Entra ID directory that belongs to a domain controlled by the organization. To become the first Global Administrator and recover admin access, the standard path is:
- Verify that the tenant is associated with the owned domain
- Confirm in the domain registrar that
lockedingarage.com.auis registered and under control. - Check whether this domain is already verified in another Microsoft 365/Entra tenant. If the registrar shows the domain is paid for but not verified in the home tenant, it may be attached to an unmanaged directory.
- For unmanaged directories created via self-service signup, a global admin can perform an admin takeover. See the guidance for internal admin takeover of unmanaged accounts created by self-service sign-up.
- Confirm in the domain registrar that
- Use the admin takeover / tenant recovery path
- For unmanaged ("shadow") tenants created by self-service sign-up, perform an internal admin takeover. This process is designed specifically so an organizational owner of the domain can become the first admin:
- Sign up to a Microsoft cloud service (for example, Power BI) using an account in the
lockedingarage.com.audomain. - This launches the admin takeover wizard, which walks through proving control of the domain and then promotes the account to admin for that unmanaged tenant.
- Sign up to a Microsoft cloud service (for example, Power BI) using an account in the
- The takeover process relies on domain verification (typically via DNS records) to prove ownership of
lockedingarage.com.au, which matches the requirement to prove domain ownership via TXT record.
- For unmanaged ("shadow") tenants created by self-service sign-up, perform an internal admin takeover. This process is designed specifically so an organizational owner of the domain can become the first admin:
- If the tenant is not simply unmanaged, or takeover fails, use Microsoft support / Data Protection team
- When there is no accessible Global Administrator and self-service recovery (SSPR, MFA reset, etc.) is not available, Microsoft’s Data Protection team handles tenant admin recovery.
- Open a support request specifically for tenant access recovery / admin lockout:
- If access to any Microsoft 365 or Azure portal is available under another tenant, use that tenant to open a support ticket and clearly state that this is for admin recovery of a different tenant (provide the tenant ID
8310a254-1096-469a-bbc9-cd8484db7e0cand the domainlockedingarage.com.au). - If no portal access is available, call Microsoft using the global customer service phone numbers and request escalation to the Data Protection team for tenant admin recovery.
- If access to any Microsoft 365 or Azure portal is available under another tenant, use that tenant to open a support ticket and clearly state that this is for admin recovery of a different tenant (provide the tenant ID
- The Data Protection team can:
- Reset credentials of an administrator account.
- Help claim ownership of tenants that belong to the organization.
- Be prepared to provide:
- Proof of domain ownership (DNS TXT record, registrar information).
- Business documentation tying the organization to
lockedingarage.com.au.
- Understand what Microsoft for Nonprofits / other programs can and cannot do
- All tenant ownership and access decisions are handled through Microsoft 365 support and the Data Protection process; program teams (such as Microsoft for Nonprofits) cannot bypass identity verification or directly assign Global Administrator.
- They can assist with documentation and routing, but the actual assignment of a Global Administrator for the tenant is done only after identity verification through standard support channels.
- If the tenant is inaccessible due to inactivity
- If the tenant has been blocked with error
AADSTS5000225: This tenant has been blocked due to inactivity, the tenant administrator must contact Microsoft (via the global support phone numbers) within 20 days of the tenant entering the inactive state to request reactivation. - After 20 days in this state, the tenant is deleted and cannot be recovered.
- If the tenant has been blocked with error
In summary, to be assigned as the first Global Administrator for the tenant:
- First attempt an internal admin takeover of the unmanaged directory using a
lockedingarage.com.auaccount and domain verification. - If that does not work or the tenant is not simply unmanaged, contact Microsoft support (phone or via another tenant) and request Data Protection / tenant admin recovery, providing tenant ID and proof of domain ownership so Microsoft can validate ownership and assign or reset a Global Administrator.
References:
- Discover your Microsoft cloud footprint FAQ
- Internal admin takeover
- Tenant inaccessible due to inactivity
- Tenant access recovery
- Global Admin Locked out - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- 7 Day Old Azure Account: AADSTS5000225: This tenant has been blocked due to inactivity. - Microsoft Q&A