A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Because the business account is protected by Microsoft Entra multifactor authentication and all Authenticator registrations and other methods were removed, only Microsoft support (Data Protection team) can reset MFA for a sole Global Administrator.
There is no self-service way to bypass or reset MFA when:
- The Microsoft Authenticator registrations were deleted,
- No alternative MFA methods (SMS, phone, email, security key) are available, and
- There is no other Global Admin in the tenant.
Use these steps:
- Confirm there is no other Global Administrator
- If any other Global Admin exists, that admin must:
- Sign in to the Azure/Microsoft Entra admin portal.
- Go to Users → All users → [your user] → Authentication methods.
- Select Require re-register multifactor authentication.
Next sign-in will prompt a fresh MFA setup in Microsoft Authenticator.
- If any other Global Admin exists, that admin must:
- If you are the only Global Admin (your case)
Microsoft’s Data Protection team must verify identity and reset MFA:- Call Microsoft support using the official Customer service phone numbers page referenced in the context.
- When the IVR/automated system asks questions, answer along these lines (as shown in the referenced Q&A answers):
- Problem: say “Authenticator” or “lost account / can’t pass MFA”.
- Product: “Office 365 for business” or “Microsoft 365 for business”.
- Account type: “For companies”.
- Are you an administrator?: “Yes”.
- Any other admins?: “No”.
- Do you need a service request?: “Yes, I need to create a ticket with the Data Protection team to reset my MFA.”
- Clearly state:
- You are the only Global Administrator for the tenant.
- You deleted all accounts from Microsoft Authenticator and signed out of all devices.
- You know the password but cannot complete MFA and have no other verification methods.
- You need MFA reset / re-registration for your admin account.
- If phone support is hard to reach – trial tenant workaround
If it is impossible to get to a live agent via phone in your region, use the documented workaround from the Q&A posts:- Sign up for a temporary Microsoft 365 trial tenant (any business plan) using a different email.
- After the trial tenant is created, go to the Microsoft 365 Admin Center for that new tenant.
- In Help & support, open a support ticket. In the ticket:
- Explain that this is a separate trial tenant used only to contact support.
- Provide:
- The admin UPN/email of the locked business account.
- The tenant domain name of the locked tenant.
- A description of the issue: only Global Admin, lost Authenticator, no other MFA methods, cannot sign in to admin portals.
- Request to be connected to the Data Protection / Tenant Recovery team to reset MFA.
- After the original tenant issue is resolved, cancel the trial subscription to avoid charges.
Once Data Protection resets MFA, the next time sign-in occurs on the business account, the portal will prompt to set up Microsoft Authenticator again (scan QR code, approve sign-in, etc.).
Until Microsoft support completes this process, the account cannot be accessed or the Authenticator app reset.
References:
- Common problems with two-step verification for a work or school account
- I can't sign in to my Microsoft account
- Use a screen reader to set up and troubleshoot multifactor authentication
- I cant log in to my business account because it is requiring Authenticator app which I do not have - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Global Admin Locked out - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A