A cloud-based identity and access management service for securing user authentication and resource access
Data Protection cases for tenant admin lockouts are handled only through Microsoft Support; there is no direct phone number or separate contact channel for the Data Protection team.
From the documented and community-supported process:
- Open or continue working through a Microsoft Support ticket
- Data Protection is engaged internally by Microsoft once a support engineer confirms the tenant-lockout / sole-admin scenario.
- Follow the guidance in the ticket email: replying to the existing case email thread is the supported way to add notes or request escalation (including asking for a manager or case escalation).
- If phone contact is needed, use the global customer service numbers and drive the IVR to a live agent
- Call the appropriate number from Customer service phone numbers - Microsoft Support.
- Ignore the initial 30-second message suggesting self-service links and wait for menu options.
- When prompted by the IVR, use a path like:
- Press 1 for business email user.
- Press 1 again for technical support.
- In automated-dialog countries, answer along these lines:
- Problem type: say “Authenticator” or “Lost account”.
- Product: “Office 365 for business”.
- Education or company: “For companies”.
- Are you an administrator?: “Yes”.
- Any other admins?: “No”.
- Do you need a service request?: “Yes – I need to create a ticket and speak with the Data Protection team.”
- Once connected to a human agent, reference the existing ticket number and explicitly request that the case be routed/expedited with the Data Protection team because the global admin is locked out.
- If unable to reach an agent at all, use a temporary trial tenant as a workaround
- Create a new Microsoft 365 trial tenant (any business plan) so that the Microsoft 365 admin center can be accessed.
- In the new tenant’s Microsoft 365 admin center, go to Help & support and open a new support request.
- In that ticket, clearly state that support is needed for a different existing tenant where the global admin is locked out and that the Data Protection team must be engaged for MFA/admin recovery.
- Provide the original tenant’s domain, locked admin UPN, and the existing ticket number so support can associate and escalate correctly.
- After resolution, cancel the trial subscription to avoid charges.
- Expected timelines
- Community and moderator guidance indicates these cases can take multiple days; some reports mention up to about a week depending on verification complexity and region.
- There is no documented faster “backdoor” to Data Protection beyond:
- An active support ticket, plus
- Phone escalation via customer service, or
- A second ticket from a trial tenant if normal channels fail.
There is no alternative direct email, portal, or phone queue for the Data Protection team beyond working through Microsoft Support with the above methods.
References:
- Preventing tenant lockouts
- How to get support in the Microsoft Intune admin center
- I cant log in to my business account because it is requiring Authenticator app which I do not have - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A