A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
To regain access when Microsoft Authenticator is lost and there are no alternative MFA methods configured, the only supported path is to work with Microsoft support, specifically the Data Protection team, because this is a tenant admin lockout scenario.
Use these steps:
- Contact Microsoft support by phone and ask for the Data Protection team
- Call the regional number listed under Customer service phone numbers - Microsoft Support:
global customer service phone numbers. - When the IVR/agent asks about the issue, clearly state that:
- This is about Microsoft Authenticator / MFA.
- The product is Office 365 / Microsoft 365 / Partner Center for business.
- The account is a company (work) account, not personal.
- This is a tenant admin lockout and there is no other global admin.
- MFA is enforced and the only method is Microsoft Authenticator on a lost phone, with no SMS/email/backup methods configured.
- Ask explicitly to create a service request and escalate to the Microsoft Data Protection team to reset the MFA/authentication methods for the admin account.
- Call the regional number listed under Customer service phone numbers - Microsoft Support:
- Be ready to verify identity and tenant ownership
The Data Protection team will follow strict verification procedures. Be prepared with:- Admin account sign-in name (e.g.,
******@onmicrosoft.com). - Tenant details (tenant name,
*.onmicrosoft.comdomain). - Business information and contact details associated with the subscription.
- Any billing or subscription identifiers they request.
After verification, they can reset MFA for the locked admin so that sign-in can be completed and a new Authenticator registration or additional methods (SMS, alternate email, etc.) can be configured.
- Admin account sign-in name (e.g.,
- If phone support is hard to reach, create a temporary trial tenant to open a ticket (fallback option)
- Sign up for a new Microsoft 365 trial tenant (separate from the locked one).
- Go to the Microsoft 365 admin center for that new tenant and open a Support → Help & support request.
- In the ticket, clearly state that the issue is with a different existing tenant where the only global admin is locked out due to Microsoft Authenticator MFA and needs Data Protection team assistance to reset MFA.
- Provide the locked tenant’s admin UPN and tenant domain and explain that the new tenant is only being used to reach support.
- Once resolved, cancel the trial subscription to avoid charges.
- After access is restored
- Sign in to the restored admin account and:
- Re-register Microsoft Authenticator.
- Add additional MFA methods (SMS, alternate phone, email, security key) where allowed.
- Consider creating at least one break-glass emergency access account in Microsoft Entra ID so that a similar lockout does not happen again. See: Manage emergency access accounts in Microsoft Entra ID.
- Sign in to the restored admin account and:
Because this is a single-admin lockout with no backup methods, only Microsoft’s Data Protection process can reset the MFA; it cannot be done self-service or by community/forum moderators.
References:
- Troubleshoot sign-in issues and account access problems
- Security requirements to use Partner Center or Partner Center APIs
- Mandating multifactor authentication (MFA) for your partner tenant
- Common problems with two-step verification for a work or school account
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- How Do I Regain Access to My Account After Losing Access to Microsoft Authenticator? (Urgent Request). - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Microsoft Authenticator app doesn't show 6-digit OTP code - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A