Global admin locked in MFA security registration loop

Jessica Weigh 0 Reputation points
2026-03-10T18:11:41.0833333+00:00

Global admin locked in MFA security registration loop in new sister Microsoft 365 tenant. SMS, voice, and email verification all return "We ran into a problem." Unable to complete security info registration or access Entra admin center to disable Security Defaults. I believe StrongAuthRegistrationRequired flag needs to be removed. I have submitted a ticket and only received one phone call from an agent who said he was escalating but it has been greater than 24 hours and no one else has contacted me and there are no other notes in the Service Request section.

I do not know how many more times I can call the support number and talk to robots before I completely lose it.

Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Newest
  1. AI answer

    2026-03-10T18:12:26.19+00:00

    For a global admin who is stuck in an MFA/security info registration loop and cannot reach the Entra admin center, the only viable paths are:

    1. Try an alternate MFA/sign-in method if any exist
    • If any other verification methods were previously configured (for example, Microsoft Authenticator, different phone number, or alternate method), use “Other verification options” on the sign-in screen and attempt those methods instead of SMS/voice/email.
    • If repeated attempts have been made, Microsoft Entra MFA may be temporarily throttling sign-ins. Wait and retry later or use a different MFA method if available.
    1. Use another admin to reset MFA (if any exist)
    • If there is any other Global Administrator or an admin with the right role in the tenant, that admin can:
      1. Sign in to the Azure portal → Microsoft Entra ID → Users.
      2. Open the affected global admin’s user profile.
      3. Use Authentication methods → Require re-register multifactor authentication so the user can complete MFA setup again.
      4. Also verify that Block sign in is not enabled on the account.
    • This is the standard recovery path when at least one other admin exists.
    1. If there is no other admin and the only global admin is locked When the only global admin is locked in MFA and cannot complete StrongAuth registration, this is treated as a tenant lockout scenario. In that case, only Microsoft support (Data Protection / Tenant Recovery) can intervene:
    • Microsoft has a dedicated Data Protection team with tools and processes to verify identity and restore access when the only admin is locked out due to MFA.
    • Forum moderators and normal support channels cannot directly change MFA or StrongAuth flags; they escalate to this team via a support ticket.
    • The correct next step is to persist with the existing support request and ensure it is clearly categorized as a tenant lockout / global admin locked out due to MFA so it reaches the Data Protection team.

    If the current ticket appears stalled:

    • Call the Microsoft 365 for business support number again and reference the existing Service Request ID.
    • Explicitly state:
      • This is a tenant lockout.
      • The only global admin cannot complete MFA/security info registration.
      • SMS/voice/email all fail with “We ran into a problem.”
      • StrongAuth registration cannot be completed and Security Defaults cannot be disabled because there is no portal access.
    • Ask the agent to escalate to the Data Protection / Tenant Recovery team and to add detailed notes to the existing ticket.

    If absolutely no way to reach support from the locked tenant:

    • As described in similar cases, one workaround is to create a separate trial Microsoft 365 tenant, go to its Microsoft 365 admin center, and open a support ticket from there.
    • In that ticket, clearly state that the issue concerns a different existing tenant where the only global admin is locked out by MFA and needs MFA/security info reset.
    • This does not give access to the locked tenant directly; it is only a channel to reach support and the Data Protection team.
    1. What cannot be done by the admin directly
    • The StrongAuthRegistrationRequired flag and MFA state for the only global admin cannot be changed by the admin without first passing MFA, so there is no self-service fix from the portal or PowerShell in this condition.
    • Only:
      • Another admin with sufficient rights, or
      • Microsoft support (Data Protection / Tenant Recovery)
      can reset MFA/StrongAuth or bypass the registration requirement.

    Given the described state (new tenant, only global admin, all MFA methods failing, stuck in registration loop), the correct and only supported resolution is escalation through Microsoft support to the Data Protection team to reset MFA/registration on that account.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.