MFA Reset Required – Global Admin Locked Out (Microsoft Entra)

John Tairis 15 Reputation points
2026-03-16T11:56:58.1366667+00:00

Hello Microsoft Support Team,

 I have an urgent access issue with my administrator account:

 🛑Issue:

I lost access to my old mobile device on which the Microsoft Authenticator app was configured. As a result:

  • I can no longer complete MFA
  • I cannot access his mailbox
  • I am locked out of the Microsoft 365 Admin Center / Entra Admin Center for  domain.

is there any email/support link where i can ask to: reset of the MFA / authentication methods for the above account, so that Microsoft Authenticator can be re-registered on a new mobile device.

Thank you

Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Newest
  1. AI answer

    2026-03-16T11:57:14.6466667+00:00

    For a work/school Microsoft Entra ID global admin who is locked out because Microsoft Authenticator is unavailable and there is no alternate MFA method configured, the recovery path depends on whether there is another admin in the tenant.

    1. If there is another Global/Authentication admin in the tenant
      • That admin signs in to the Microsoft Entra admin center: https://entra.microsoft.com
      • Go to Entra ID → Users → select the locked-out admin account.
      • Open Authentication methods.
      • Select Require re-register multifactor authentication.
      • After this, sign-in will prompt to set up MFA again on the new mobile device.
      This is the standard, supported way to reset MFA methods for another user.
    2. If there is no other Global Admin (sole admin locked out)
      • This is treated as a tenant lockout / Data Protection scenario.
      • Direct self-service reset is not possible; Microsoft Support must verify tenant ownership and reset MFA.
      • Use the global customer service phone numbers listed in the documentation to reach support: see “Customer service phone numbers - Microsoft Support” in the references below.
      • When calling, clearly state:
        • This is a business / company Microsoft 365 / Entra tenant.
        • The caller is the only global administrator.
        • MFA is enforced and the only method (Microsoft Authenticator) is no longer accessible.
        • A Data Protection / Tenant Recovery case is needed to reset MFA for the global admin.
      • Support will route the case to the Data Protection team, who will guide through verification (ownership proof) and then reset MFA registration so it can be configured again on the new device.
    3. If unable to reach the right support team directly
      • One documented workaround is to create a temporary new tenant (for example via a Microsoft 365 Business trial), sign in as that tenant’s admin, and open a support ticket from there requesting Data Protection assistance for the original tenant. This is only a channel to reach support; the Data Protection team will still verify ownership of the original tenant before making changes.
    4. General guidance and prevention
      • For future resilience, configure multiple MFA methods (e.g., Authenticator + phone) and ensure there is more than one global admin or at least a Privileged Authentication Administrator, so another admin can reset MFA if one is locked out.

    There is no direct email address for MFA reset; the supported path is via Microsoft Support (phone or ticket) and, for sole-admin lockout, escalation to the Data Protection team.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.