A cloud-based identity and access management service for securing user authentication and resource access
This situation is a full tenant lockout caused by Conditional Access. Recovery requires out-of-band admin access; it cannot be fixed from inside the tenant once all Global Admins are blocked.
Actionable steps based on documented paths:
- Check for any unblocked admin or break-glass account
- Verify whether there are:
- Any other Global Administrator accounts that might still be able to sign in (for example, cloud-only accounts, accounts with different MFA methods, or accounts excluded from the new Conditional Access policies).
- Any emergency access / break-glass accounts that were created earlier and excluded from Conditional Access.
- If such an account exists and can sign in, use it to:
- Go to Microsoft Entra admin center → Conditional Access.
- Disable or edit the CA policies that:
- Require compliant/registered devices for all users/admins.
- Block legacy auth (if it is unintentionally impacting sign-in paths you need for recovery).
- Re-enable access for at least Global Admins, then for users.
- Having at least two cloud-only emergency access accounts with Global Administrator role.
- Excluding these emergency accounts from Conditional Access policies to prevent lockout.
- Verify whether there are:
- If no admin can sign in: treat as tenant lockout and escalate to Microsoft Support When all admins are locked out and no break-glass account exists or works, the only supported recovery path is via Microsoft Support / Data Protection team:
- This is the same pattern documented for:
- Conditional Access misconfiguration lockouts.
- Global Admins locked out due to MFA issues.
- If any other unblocked admin exists (not your case, but for completeness):
- That admin signs in and disables or fixes the Conditional Access policy.
- If no admin can update the policy:
- A support request must be opened so Microsoft support can review and, after confirming ownership, update Conditional Access policies that prevent access.
- Call Microsoft support by phone
- Use the published customer service phone numbers for your region.
- Clearly state that this is a tenant lockout / admin lockout due to Conditional Access and that:
- All Global Admins are blocked.
- No break-glass account exists or is usable.
- No one can sign in to the Microsoft 365/Azure admin portals.
- Ask the frontline agent to open a service request for Data Protection / Tenant Recovery for a locked tenant.
- If subscription is via a partner/reseller
- Contact the partner/reseller and have them open a service request on your behalf, indicating that the tenant’s Global Admins are locked out and Conditional Access is blocking all sign-ins.
- Optional fallback: create a temporary trial tenant to open a ticket
- Create a new, separate Microsoft 365 trial tenant.
- From that new tenant’s admin center, open a support ticket.
- In the ticket, explicitly state that:
- The issue is with a different, existing tenant where all Global Admins are locked out by Conditional Access.
- Provide the locked tenant’s domain and admin UPNs.
- Describe that every sign-in is blocked (error 53003) and no admin can access Conditional Access to fix policies.
- This trial tenant is only a communication channel with support; it does not give access to the locked tenant’s data.
- Verify identity and administrative rights for the locked tenant.
- Reset MFA or adjust Conditional Access policies that are causing the lockout.
- This is the same pattern documented for:
- After Microsoft restores access: harden and prevent recurrence Once support has restored access (for example, by disabling or modifying the blocking Conditional Access policies):
- Create and configure emergency access accounts
- Create at least two cloud-only Global Administrator accounts.
- Ensure they are not federated or synced from on-premises.
- Exclude at least one of these accounts from all Conditional Access policies, including MFA requirements, so that there is always a guaranteed access path.
- Use long, complex passwords and monitor sign-in activity for these accounts with high-severity alerts.
- Redesign Conditional Access policies
- Avoid blanket policies that apply to all admins without exclusions.
- Always exclude:
- Emergency access / break-glass accounts.
- Service accounts and service principals (and instead use Conditional Access for workload identities where appropriate).
- Test new policies in report-only mode or on a pilot group before enforcing them tenant-wide.
- Implement resilient access control
- Provide multiple authentication methods per user (for example, Authenticator app, OATH token, SMS) so that loss of one factor does not cause lockout.
- Consider phishing-resistant MFA for admins (for example, FIDO2 passkeys, certificate-based authentication) and use authentication strength-based Conditional Access where appropriate.
- Ensure Global Admin redundancy
- Maintain at least two Global Admin accounts with distinct credentials and MFA methods.
- Document emergency procedures so that admins know how to use break-glass accounts and how to contact Microsoft support if lockout occurs.
- Create and configure emergency access accounts
In this scenario, because every sign-in is blocked and no admin can modify Conditional Access, the only viable next step is to work with Microsoft Support / Data Protection to have them adjust or disable the blocking Conditional Access policies on the backend after verifying tenant ownership.
References:
- Troubleshoot sign-in problems with Conditional Access
- Privileged Access
- Preventing tenant lockouts
- Create a resilient access control management strategy with Microsoft Entra ID
- Require MFA for administrators
- Apply Conditional Access policies to Private Access apps
- Enable compliant network check with Conditional Access
- Microsoft-managed Conditional Access policies
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Global Admin Locked out - Microsoft Q&A
- Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- I need to reset my mfa methods - Microsoft Q&A
- Azure has blocked myphone number for SMS verification due to a “bad reputation” flag - Microsoft Q&A