Microsoft 365 features that help users manage their subscriptions, account settings, and billing information.
The sign-in issue is caused by being unable to complete multifactor authentication (MFA), not by the email address itself. Because the account is a global administrator and there is a mismatch between the MFA prompt (6‑digit code) and what the Microsoft Authenticator app is showing (8‑digit code), normal self-service recovery is blocked and admin-level recovery is required.
Since this is a global admin lockout with no working MFA method and mission‑critical workloads, the supported path is to have Microsoft reset the MFA registration through the Data Protection/Tenant Recovery process. This must be done by Microsoft Support; it cannot be fixed from the portal while locked out.
Use the following approach:
- Contact Microsoft support by phone and request Data Protection/Tenant Recovery
- Call the Microsoft global customer service/support phone number for your region. Use the phone list referenced in the documentation: see “Customer service phone numbers - Microsoft Support” in the context.
- When interacting with the IVR/agent, clearly state:
- This is an Azure/Microsoft 365 for business tenant.
- The caller is the only global administrator.
- MFA is blocking access because the configured method (Microsoft Authenticator) no longer works as expected.
- A Data Protection / Tenant Recovery / admin MFA reset is required.
- Be prepared to prove tenant ownership
- The Data Protection team will verify identity and tenant ownership (for example, via business documentation, subscription information, domain ownership, billing details, etc.).
- After verification, they can reset or clear the MFA registration for the global admin so that a new MFA method can be configured on next sign‑in.
- If phone support is difficult to reach
- As described in similar resolved cases, one workaround is to create a temporary trial Microsoft 365 tenant, sign in as its admin, and open a support ticket from that admin center explicitly asking to be connected to the Data Protection team for the original tenant. However, the primary and recommended method remains calling support directly.
Once Microsoft resets the MFA for the global admin, sign in again with the same personal email and password, then complete MFA registration afresh (Microsoft Authenticator, phone, SMS, etc.). After that, access to the Azure portal and subscriptions will be restored.
References:
- Common problems with two-step verification for a work or school account
- You don't receive a text or voice call that contains the verification code for Microsoft Entra multifactor authentication
- Global Admin Locked out - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Error Code: 399287 - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- Azure has blocked myphone number for SMS verification due to a “bad reputation” flag - Microsoft Q&A