A cloud-based identity and access management service for securing user authentication and resource access
For a work/school Microsoft Entra ID global admin who is locked out because Microsoft Authenticator is unavailable and there is no alternate MFA method configured, the recovery path depends on whether there is another admin in the tenant.
- If there is another Global/Authentication admin in the tenant
- That admin signs in to the Microsoft Entra admin center: https://entra.microsoft.com
- Go to Entra ID → Users → select the locked-out admin account.
- Open Authentication methods.
- Select Require re-register multifactor authentication.
- After this, sign-in will prompt to set up MFA again on the new mobile device.
- If there is no other Global Admin (sole admin locked out)
- This is treated as a tenant lockout / Data Protection scenario.
- Direct self-service reset is not possible; Microsoft Support must verify tenant ownership and reset MFA.
- Use the global customer service phone numbers listed in the documentation to reach support: see “Customer service phone numbers - Microsoft Support” in the references below.
- When calling, clearly state:
- This is a business / company Microsoft 365 / Entra tenant.
- The caller is the only global administrator.
- MFA is enforced and the only method (Microsoft Authenticator) is no longer accessible.
- A Data Protection / Tenant Recovery case is needed to reset MFA for the global admin.
- Support will route the case to the Data Protection team, who will guide through verification (ownership proof) and then reset MFA registration so it can be configured again on the new device.
- If unable to reach the right support team directly
- One documented workaround is to create a temporary new tenant (for example via a Microsoft 365 Business trial), sign in as that tenant’s admin, and open a support ticket from there requesting Data Protection assistance for the original tenant. This is only a channel to reach support; the Data Protection team will still verify ownership of the original tenant before making changes.
- General guidance and prevention
- For future resilience, configure multiple MFA methods (e.g., Authenticator + phone) and ensure there is more than one global admin or at least a Privileged Authentication Administrator, so another admin can reset MFA if one is locked out.
There is no direct email address for MFA reset; the supported path is via Microsoft Support (phone or ticket) and, for sole-admin lockout, escalation to the Data Protection team.
References:
- Manage user authentication methods for Microsoft Entra multifactor authentication
- Can't use Azure Multi-Factor Authentication to sign in to cloud services after you lose your phone or the phone number changes
- About administrator roles in the Microsoft 365 admin center
- Global Admin Locked out - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- I need to reset my mfa methods - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A