URGENT: Global Administrator locked out after enabling Conditional Access

daniel rau 5 Reputation points
2026-03-11T04:25:21.4133333+00:00

I am the GA of a 10-person startup. Today (March 10, 2026) an GA account was compromised via an AiTM session token theft attack. An attacker used the breached account account to send phishing emails to external contacts.        

                                                                                                     

Our second GA did the following while we scraped Azure activity logs to identify the breach:

  1. Rest all passwords,

  2. Revoked all sign-in sessions via Microsoft Graph API

  3. Disabled Security Defaults to enable Conditional Access

  4. Created CA policy blocking the identified attacker's IP range

  5. Created CA policy to require MFA - but made the CA only grant approved / registered devices by our GA. MFA was already in-place on every user device, however we had not registered / approved specific devices.

  6. Created CA policy "Block Legacy Auth" — blocking Exchange ActiveSync and Other clients.

Thus the entire org was booted out of their sessions with no ability to login.

Now every sign-in across the entire tenant is blocked with error 53003. No user can sign in to any Microsoft service — Entra, Azure Portal, Outlook, Teams, Azure CLI, PowerShell, nothing. Users cannot register MFA because they cannot sign in. Complete catch-22.

I've tried

  - Signing in via browser, InPrivate, Azure CLI, PowerShell device code flow — all blocked with 53003

  - Creating new user accounts via Graph API — also blocked when they try to sign in

  - Resetting passwords via Graph API — cannot reset Global Admin passwords

  - Registering MFA methods via Graph API — app lacks UserAuthenticationMethod.ReadWrite.All permission

  - Re-enabling Security Defaults via Graph API — app lacks Policy.ReadWrite.SecurityDefaults permission

  - Modifying CA policies via Graph API — app lacks Policy.ReadWrite.ConditionalAccess permission

  - The app cannot grant itself new permissions (lacks AppRoleAssignment.ReadWrite.All)

 

Have also called multiple Microsoft support numbers but cannot reach a live agent & emailed existing Microsoft support case contacts during normal working hours with no response.

Pls, pls, pls escalate this to Sev A and get me on the phone.

We are mid negotiation of a big contract.

Microsoft Security | Microsoft Entra | Microsoft Entra ID

2 answers

Sort by: Oldest
  1. AI answer

    2026-03-11T04:25:50.74+00:00

    This situation is a full tenant lockout caused by Conditional Access. Recovery requires out-of-band admin access; it cannot be fixed from inside the tenant once all Global Admins are blocked.

    Actionable steps based on documented paths:

    1. Check for any unblocked admin or break-glass account
      • Verify whether there are:
        • Any other Global Administrator accounts that might still be able to sign in (for example, cloud-only accounts, accounts with different MFA methods, or accounts excluded from the new Conditional Access policies).
        • Any emergency access / break-glass accounts that were created earlier and excluded from Conditional Access.
      • If such an account exists and can sign in, use it to:
        1. Go to Microsoft Entra admin center → Conditional Access.
        2. Disable or edit the CA policies that:
          • Require compliant/registered devices for all users/admins.
          • Block legacy auth (if it is unintentionally impacting sign-in paths you need for recovery).
        3. Re-enable access for at least Global Admins, then for users.
      Reference guidance explicitly recommends:
      • Having at least two cloud-only emergency access accounts with Global Administrator role.
      • Excluding these emergency accounts from Conditional Access policies to prevent lockout.
    2. If no admin can sign in: treat as tenant lockout and escalate to Microsoft Support When all admins are locked out and no break-glass account exists or works, the only supported recovery path is via Microsoft Support / Data Protection team:
      • This is the same pattern documented for:
        • Conditional Access misconfiguration lockouts.
        • Global Admins locked out due to MFA issues.
      Documented process:
      1. If any other unblocked admin exists (not your case, but for completeness):
        • That admin signs in and disables or fixes the Conditional Access policy.
      2. If no admin can update the policy:
        • A support request must be opened so Microsoft support can review and, after confirming ownership, update Conditional Access policies that prevent access.
      Since no one in the tenant can sign in to open a ticket from the affected tenant, use one of these paths (as documented in similar lockout/MFA cases):
      • Call Microsoft support by phone
        • Use the published customer service phone numbers for your region.
        • Clearly state that this is a tenant lockout / admin lockout due to Conditional Access and that:
          • All Global Admins are blocked.
          • No break-glass account exists or is usable.
          • No one can sign in to the Microsoft 365/Azure admin portals.
        • Ask the frontline agent to open a service request for Data Protection / Tenant Recovery for a locked tenant.
      • If subscription is via a partner/reseller
        • Contact the partner/reseller and have them open a service request on your behalf, indicating that the tenant’s Global Admins are locked out and Conditional Access is blocking all sign-ins.
      • Optional fallback: create a temporary trial tenant to open a ticket
        • Create a new, separate Microsoft 365 trial tenant.
        • From that new tenant’s admin center, open a support ticket.
        • In the ticket, explicitly state that:
          • The issue is with a different, existing tenant where all Global Admins are locked out by Conditional Access.
          • Provide the locked tenant’s domain and admin UPNs.
          • Describe that every sign-in is blocked (error 53003) and no admin can access Conditional Access to fix policies.
        • This trial tenant is only a communication channel with support; it does not give access to the locked tenant’s data.
      Microsoft’s Data Protection / Tenant Recovery team has specific tools and processes to:
      • Verify identity and administrative rights for the locked tenant.
      • Reset MFA or adjust Conditional Access policies that are causing the lockout.
    3. After Microsoft restores access: harden and prevent recurrence Once support has restored access (for example, by disabling or modifying the blocking Conditional Access policies):
      1. Create and configure emergency access accounts
        • Create at least two cloud-only Global Administrator accounts.
        • Ensure they are not federated or synced from on-premises.
        • Exclude at least one of these accounts from all Conditional Access policies, including MFA requirements, so that there is always a guaranteed access path.
        • Use long, complex passwords and monitor sign-in activity for these accounts with high-severity alerts.
      2. Redesign Conditional Access policies
        • Avoid blanket policies that apply to all admins without exclusions.
        • Always exclude:
          • Emergency access / break-glass accounts.
          • Service accounts and service principals (and instead use Conditional Access for workload identities where appropriate).
        • Test new policies in report-only mode or on a pilot group before enforcing them tenant-wide.
      3. Implement resilient access control
        • Provide multiple authentication methods per user (for example, Authenticator app, OATH token, SMS) so that loss of one factor does not cause lockout.
        • Consider phishing-resistant MFA for admins (for example, FIDO2 passkeys, certificate-based authentication) and use authentication strength-based Conditional Access where appropriate.
      4. Ensure Global Admin redundancy
        • Maintain at least two Global Admin accounts with distinct credentials and MFA methods.
        • Document emergency procedures so that admins know how to use break-glass accounts and how to contact Microsoft support if lockout occurs.

    In this scenario, because every sign-in is blocked and no admin can modify Conditional Access, the only viable next step is to work with Microsoft Support / Data Protection to have them adjust or disable the blocking Conditional Access policies on the backend after verifying tenant ownership.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

  2. VEMULA SRISAI 13,990 Reputation points Microsoft External Staff Moderator
    2026-03-13T10:54:33.3366667+00:00

    drau To resolve this, we have engaged our Data Protection team through a support ticket. They will reach out to you via email or phone to help restore access to the tenant and assist in resolving the issue.

    Once the issue has been resolved by our support team, please feel free to revisit and kindly click "Accept Answer," as this will be helpful to other community members facing similar issues.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.