unable to enter our admin.microsoft,com account using our email ID

Sunil 0 Reputation points
2026-03-22T09:37:54.5066667+00:00

After buying a domain, using Microsoft Authenticator App, everything was set up properly. After that, we have tried change from ******@companyname.onmicrosoft.com to ******@companyname.com in authenticator. It did not allow. Hence, added directly ******@companyname.com separately in the App and it worked. We thought now we can remove the 1st added ******@companyname.onmicrosoft.com from Microsoft Authenticator App. We removed. After that we could not get into our admin account. We have tried every thing and nothing worked out. Need help to resolve this issue, as admin account is not accessible.

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Newest
  1. AI answer

    2026-03-22T09:38:09.0433333+00:00

    Because the original global admin sign-in was protected only by the Microsoft Authenticator registration that was removed, the tenant admin account is now effectively locked out and cannot complete MFA.

    When there is only one admin and that admin loses access to Microsoft Authenticator (or its original registration), self-service recovery is not possible. In this situation, Microsoft’s Data Protection team must manually verify identity and restore access.

    Use these steps:

    1. Contact Microsoft support by phone and have a ticket opened to the Data Protection team for a tenant lockout / MFA issue on the global admin:
      • Call the appropriate number from Customer service phone numbers.
      • When the IVR asks what the problem is, clearly state it is an Authenticator / MFA lockout for an Office 365 / Microsoft 365 for business account.
      • Confirm it is a company account, that the caller is the administrator, and that there are no other administrators in the organization.
      • Ask the agent to open a service request and route it to the Data Protection team to restore access to the locked tenant.
    2. If phone support is difficult to reach, create a temporary trial tenant only to open a support ticket:
      • Sign up for a free Microsoft 365 trial tenant (any enterprise/business plan) and complete setup.
      • Go to the Microsoft 365 Admin Center for the trial tenant and open Help & support.
      • In the ticket, clearly state that:
        • There is a different, existing Microsoft 365 tenant where the global admin is locked out due to Authenticator/MFA.
        • Provide the locked tenant’s domain (for example, companyname.onmicrosoft.com and companyname.com) and the admin UPN/email.
        • Explain that the original Microsoft Authenticator registration was removed and no other MFA methods or admins exist.
      • Ask for the case to be escalated to the Data Protection team to restore access.
      • After the issue is resolved, cancel the trial subscription to avoid charges.
    3. Once access is restored, sign in and immediately:
      • Re-register Microsoft Authenticator and at least one backup MFA method (phone, alternate email, or another authenticator registration).
      • Consider adding a second global admin account so that one admin can recover the other in future.

    Only Microsoft support (via the Data Protection team) can unlock this scenario; community forums and self-service tools cannot modify admin MFA or restore the removed Authenticator registration.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.