A cloud-based identity and access management service for securing user authentication and resource access
For this scenario, the MFA configuration for the account is likely in a bad state and self-service changes are not working. The supported path is to have an administrator in the Entra tenant reset the MFA registration for the affected account so that it can be re-enrolled.
Action steps:
- Sign in to the Microsoft Entra admin center with another Global Administrator account in the tenant where the MCT/Outlook account is used.
- Go to Identity → Users → All users.
- Select the affected user (the MCT Outlook account).
- Open Authentication methods for that user.
- Select Require re-register multifactor authentication.
- Have the user sign in again to the Azure portal; they will be prompted to set up MFA from scratch (new Authenticator registration or other available methods).
If there is no other Global Administrator in the tenant (the locked-out account is the only admin), the issue must be escalated to Microsoft Support/Data Protection via a support ticket or regional support phone number so they can verify tenant ownership and reset MFA from their side. Forum moderators or support can initiate this escalation, as shown in similar lockout cases.
References: