A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Because the old phone with Microsoft Authenticator is lost and there is only one admin on the tenant, this is a tenant lockout scenario that cannot be fixed self-service. The path forward is to get Microsoft’s Data Protection team to verify identity and reset the admin’s MFA.
Follow these steps:
- Try any alternative MFA methods (if configured)
- If another verification method (SMS, office phone, alternate app) was ever configured, use “Sign in another way” on the sign-in page and complete sign-in with that method.
- If no other method works or is configured, proceed to the next steps.
- Contact Microsoft Support by phone and ask for Data Protection / Tenant Recovery
Since access to the admin portal is blocked, support must be engaged by phone:- Call the appropriate number from Customer service phone numbers - Microsoft Support.
- When navigating the IVR (automated system), clearly indicate:
- Issue: Authenticator / Multi-factor authentication / cannot access admin account.
- Product: Office 365 for business or Microsoft 365 for business (company account, not personal).
- Confirm: Yes, this is a company account and Yes, you are the administrator and No, there is no other administrator.
- Ask explicitly to create a service request and escalate to the Data Protection team (sometimes called Tenant Recovery) to reset the admin’s MFA.
- Be prepared to provide tenant details (admin sign-in address, domain, company details, contact info) and pass identity verification. The Data Protection team will then work with you to reset MFA on the admin account so a new Authenticator registration can be completed.
- If unable to reach the right support team, create a temporary trial tenant to open a ticket
If the phone route keeps misrouting or agents cannot locate the tenant:- Sign up for a new Microsoft 365 trial tenant (any business/enterprise plan) using a different account.
- Sign in to the Microsoft 365 Admin Center of this new tenant.
- Go to Support → Help & support and open a ticket.
- In the ticket, clearly state that:
- You are locked out of a different, existing tenant where you are the only global admin.
- You need the Data Protection team to perform a tenant admin MFA reset / tenant recovery.
- Provide the locked tenant’s domain, admin UPN, and all relevant details and error messages.
- Work with the assigned engineer; they will involve the Data Protection team, verify identity, and reset MFA for the locked tenant.
- After recovery, cancel the trial tenant to avoid charges.
- After access is restored
Once the Data Protection team or support engineer has reset MFA and access is regained:- Re-register Microsoft Authenticator on the new phone.
- Add at least one additional MFA method (e.g., SMS, alternate phone, another app, or a second admin account) so a single device loss does not cause another lockout.
Stopping card charges or disputing payments will not restore access and may complicate the relationship with the tenant; the supported and effective route is identity verification and MFA reset via Microsoft Support/Data Protection.
References:
- Common problems with two-step verification for a work or school account
- Frequently asked questions about Microsoft Entra multifactor authentication
- Restore account credentials from Microsoft Authenticator
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- How Do I Regain Access to My Account After Losing Access to Microsoft Authenticator? (Urgent Request). - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Global Admin Locked out - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- Use a screen reader to set up and troubleshoot multifactor authentication