Please help reset MFA and verify ownership of the domain.

PhuocPH 0 Reputation points
2026-03-22T09:45:33.9233333+00:00

I am the Global Administrator of tenant bctech.edu.vn. My account is ******@bctech.edu.vn

Currently, I am locked out due to MFA (Microsoft Authenticator not showing passcode or approval request).

I no longer have access to the configured authentication methods.

This is the only Global Admin account, and I need to regain access to manage the organization.

Please help reset MFA and verify ownership of the domain.

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-03-22T09:45:46.78+00:00

    MFA for the only Global Administrator cannot be reset directly from portals when locked out. Recovery must go through Microsoft support and the Data Protection/Tenant Recovery process so identity and domain ownership can be verified.

    Follow these steps:

    1. Prepare proof of ownership
      • Collect official business documentation for the organization (registration documents, tax certificates, etc.).
      • Ensure access to email addresses and evidence that the organization owns the domain bctech.edu.vn (for example, domain registrar records or DNS control).
    2. Open a Microsoft support ticket for tenant lockout
      • Go to the Microsoft global support phone numbers page: Customer service phone numbers - Microsoft Support.
      • Call the number for the region and clearly state:
        • This is a tenant lockout.
        • The account is the only Global Administrator.
        • MFA methods are no longer accessible (Authenticator not providing code/approval).
        • Assistance is needed from the Data Protection team to reset admin credentials/MFA and verify ownership of the tenant and domain.
    3. Ask specifically for Data Protection / Tenant Recovery
      • During the call, request creation of a service request and escalation to the Data Protection team.
      • Explain that no other global admin exists who could use “Require re-register multifactor authentication,” so self-service or admin-based reset is impossible.
      • Follow their instructions to submit required documentation and complete identity verification.
    4. What Microsoft’s Data Protection team can do
      • According to the documented process, when locked out of a tenant with no other global admin, the Data Protection team can:
        • Reset credentials of an administrator account.
        • Help claim or confirm ownership of the tenant.
      • After verification, they will reset MFA/credentials so sign-in can be completed and new authentication methods (including a new Authenticator registration) can be configured.
    5. If the tenant is associated with an unmanaged or partner-created directory
      • If a Microsoft partner or reseller manages the tenant, contact that partner and ask them to open a support ticket on behalf of the organization for tenant lockout/MFA reset.
      • If the domain is tied to an unmanaged directory, a global admin can perform an admin takeover after access is restored, as described in the admin takeover guidance.

    Until Microsoft completes verification and resets the admin’s MFA/credentials, access cannot be restored by any portal or self-service flow.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.