Renaming the Microsoft 365 work account (from @fbcnmnj.onmicrosoft.com to @fbcnm-nj.org) in the cloud does not automatically update or preserve local Windows administrator rights. Windows now treats the renamed cloud account as a different identity for local sign-in/permissions, so the original local admin mapping is effectively lost.
To regain admin rights on the PC, one of the following is required (depending on how the device is joined and what access is still available):
- Sign in with another local administrator account
- If any other local admin account exists (local
Administrator, another user with admin rights), sign in with that account. - Open Settings → Accounts → Other users (or Control Panel → User Accounts) and re-add the work account as an administrator on the device.
- If any other local admin account exists (local
- Use an on-premises/domain admin (if domain-joined)
- If the PC is joined to an on-premises Active Directory domain, sign in with a domain admin account.
- Add the renamed work account (or the appropriate group) back into the local Administrators group.
- Use Microsoft 365 / Entra device management (if Azure AD joined)
- If the device is Azure AD–joined and managed, a Microsoft Entra (Azure AD) Global Administrator or Intune administrator can push a policy to add the user (or a group) back to the local Administrators group.
- If there is no other global admin, follow the account-access escalation paths in the tenant (see reference below) so another admin or Microsoft’s Data Protection team can help restore access.
- If locked out of all admin accounts
- If no admin credentials (local, domain, or Entra) are available at all, recovery requires an administrator-level reset path outside the PC itself (for example, another tenant admin, or Microsoft 365 Data Protection support for business tenants) or a full OS reinstall, which will remove existing local profiles and apps.
For tenant-level account access problems (for example, being the only global admin, or no global admin available) use the documented escalation paths:
- If the only global admin on the account and locked out, contact the Azure Data Protection team using the phone number in the reference.
- If the company has no global admin or the admin account is unusable, contact the Microsoft 365 Data Protection team via the regional support number listed in the admin support article and request help restoring admin access.
Once an admin identity is restored (local or cloud), add the desired user back to the local Administrators group and avoid renaming or removing that account without first ensuring another admin account exists on the PC.
References: