URGENT: Sole Global Admin Locked Out by MFA (MFA Reset Required for Tenant Recovery)

Tanvir Ahmed 0 Reputation points
2026-03-15T06:55:08.2233333+00:00

Hello,

I am the sole Global Administrator for my tenant and I am completely locked out.

The Situation:

Admin Account: ******@sheltechceramicsltd.onmicrosoft.com

Custom Domain: sheltechceramics.com

The Issue: I have the correct password, but I am blocked by Multi-Factor Authentication (MFA). I no longer have access to the Microsoft Authenticator app that was configured, and there are no other Global Admins in this tenant to reset it for me.

Reseller Issue: I have purchased a new subscription through a reseller (sheltechceramics2.onmicrosoft.com), but I cannot add my domain there because it is trapped in this locked tenant.

Request: I need an MFA Reset for the account ******@sheltechceramicsltd.onmicrosoft.com so I can regain access, remove my domain, and manage my organization.

I am the legal owner of the domain and have full access to my GoDaddy DNS settings. I am ready to provide any TXT verification records or business documentation (Trade License, etc.) required by the Data Protection Team to prove my identity.

I have tried calling the regional support numbers but have been unable to reach a live agent who can escalate this to the Data Protection Team.

Can a moderator please escalate this case or provide a way for the Data Protection Team to contact me?

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Oldest
  1. AI answer

    2026-03-15T06:55:32.62+00:00

    An MFA reset for a sole Global Administrator on a locked tenant can only be performed by Microsoft’s Data Protection team after verifying tenant ownership. Community moderators and this service cannot directly trigger that process or contact the team on behalf of the tenant.

    To proceed, use one of these supported paths:

    1. Contact Microsoft Data Protection / Tenant Recovery by phone (primary path)
      • Call the global customer service phone number for the region: use the numbers listed under Customer service phone numbers - Microsoft Support.
      • When interacting with the IVR/agent, clearly state:
        • The problem is with Authenticator / MFA.
        • The product is Office 365 for business / Microsoft 365 for business.
        • The account is a company (work) account, not personal.
        • Confirm being the only Global Administrator on the tenant.
        • Request creation of a service request with the Microsoft 365 Data Protection team for tenant admin MFA reset / tenant recovery.
      • Be prepared to prove ownership (for example, DNS TXT record on sheltechceramics.com, business documentation, etc.) as requested by the Data Protection team.
    2. If phone support cannot be reached reliably: create a temporary trial tenant to open a support ticket
      • Sign up for a new Microsoft 365 trial tenant (separate from both existing tenants).
      • After the trial tenant is created, go to the Microsoft 365 admin center for that new tenant.
      • Open Support → Help & support and create a support request.
      • In the ticket, clearly state:
        • This new tenant is only being used to contact support.
        • The real issue is a locked existing tenant where the account ******@sheltechceramicsltd.onmicrosoft.com is the sole Global Admin.
        • Provide the locked tenant’s domain (sheltechceramics.com) and the .onmicrosoft.com name.
        • Request escalation to the Data Protection team for MFA reset / admin recovery on the locked tenant.
      • Support may ask for domain verification (for example, TXT record in GoDaddy DNS) and business documentation before proceeding.
    3. If there were any other Global Admins (not in this case)
      • A different Global Admin could sign in to the Azure portal → Microsoft Entra ID → Users → [locked admin] → Authentication methods → Require re-register multifactor authentication, which forces MFA re-registration on next sign-in. This does not apply when there is only one Global Admin.
    4. If the tenant is through a CSP/reseller
      • If the original locked tenant was provisioned by a Cloud Solution Provider, the reseller can open a support request to Microsoft on behalf of the tenant and ask for Data Protection / tenant recovery assistance.

    Until the Data Protection team verifies ownership and resets MFA or otherwise restores access, the custom domain cannot be removed from the locked tenant and therefore cannot be attached to the new tenant.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.