A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
An MFA reset for a sole Global Administrator on a locked tenant can only be performed by Microsoft’s Data Protection team after verifying tenant ownership. Community moderators and this service cannot directly trigger that process or contact the team on behalf of the tenant.
To proceed, use one of these supported paths:
- Contact Microsoft Data Protection / Tenant Recovery by phone (primary path)
- Call the global customer service phone number for the region: use the numbers listed under Customer service phone numbers - Microsoft Support.
- When interacting with the IVR/agent, clearly state:
- The problem is with Authenticator / MFA.
- The product is Office 365 for business / Microsoft 365 for business.
- The account is a company (work) account, not personal.
- Confirm being the only Global Administrator on the tenant.
- Request creation of a service request with the Microsoft 365 Data Protection team for tenant admin MFA reset / tenant recovery.
- Be prepared to prove ownership (for example, DNS TXT record on
sheltechceramics.com, business documentation, etc.) as requested by the Data Protection team.
- If phone support cannot be reached reliably: create a temporary trial tenant to open a support ticket
- Sign up for a new Microsoft 365 trial tenant (separate from both existing tenants).
- After the trial tenant is created, go to the Microsoft 365 admin center for that new tenant.
- Open Support → Help & support and create a support request.
- In the ticket, clearly state:
- This new tenant is only being used to contact support.
- The real issue is a locked existing tenant where the account
******@sheltechceramicsltd.onmicrosoft.comis the sole Global Admin. - Provide the locked tenant’s domain (
sheltechceramics.com) and the.onmicrosoft.comname. - Request escalation to the Data Protection team for MFA reset / admin recovery on the locked tenant.
- Support may ask for domain verification (for example, TXT record in GoDaddy DNS) and business documentation before proceeding.
- If there were any other Global Admins (not in this case)
- A different Global Admin could sign in to the Azure portal → Microsoft Entra ID → Users → [locked admin] → Authentication methods → Require re-register multifactor authentication, which forces MFA re-registration on next sign-in. This does not apply when there is only one Global Admin.
- If the tenant is through a CSP/reseller
- If the original locked tenant was provisioned by a Cloud Solution Provider, the reseller can open a support request to Microsoft on behalf of the tenant and ask for Data Protection / tenant recovery assistance.
Until the Data Protection team verifies ownership and resets MFA or otherwise restores access, the custom domain cannot be removed from the locked tenant and therefore cannot be attached to the new tenant.
References:
- Troubleshoot sign-in issues and account access problems
- Global Admin Locked out - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- I need to reset my mfa methods - Microsoft Q&A
- Preventing tenant lockouts
- You don't receive a text or voice call that contains the verification code for Microsoft Entra multifactor authentication
- Common problems with two-step verification for a work or school account