Tag not monitored by Microsoft.
Because the Conditional Access policies are blocking all sign-ins and there is only one Global Administrator, recovery must go through Microsoft support and the Data Protection/Tenant Recovery process.
Use the following paths depending on what is still accessible:
- If any other admin account can still sign in (even with limited access)
- Have that admin:
- Sign in to the Azure portal and go to Microsoft Entra ID.
- Open Security → Conditional Access.
- Disable or edit the Conditional Access policy that is blocking access, or exclude the affected admin account from that policy.
- If the issue is specifically MFA preventing sign-in and another Global Admin exists, that admin can reset MFA registration for the locked-out account so it can re-register:
- In Microsoft Entra ID, go to Users.
- Select the affected user.
- Go to Authentication methods and select Require re-register multifactor authentication.
- Have that admin:
- If no other admin can sign in (sole Global Admin locked out)
- This is effectively a tenant lockout scenario. Conditional Access cannot be fixed self-service because no admin can reach the portal.
- Recovery requires Microsoft support/Data Protection to adjust the blocking Conditional Access policies after verifying ownership.
- Take these steps:
- Use the global or regional support phone numbers listed under Microsoft 365/Azure support (for example, via the contacts referenced in the documentation such as Get support - Microsoft 365 admin or the global support phone numbers mentioned for tenant recovery).
- When prompted by the automated system or support agent, clearly state that this is a tenant lockout / Conditional Access lockout and that there is only one Global Administrator.
- Ask to be routed to the Data Protection or Tenant Recovery team.
- Provide all requested verification details (tenant domain, admin UPN, subscription details, business information, and any sign-in error codes like
AADSTS53003/BlockedByConditionalAccessif available).
- Microsoft support will review and, after confirming ownership, update or disable the Conditional Access policies that prevent access so that the Global Admin can sign in again.
- If unable to open a ticket from the locked tenant
- If direct phone support is difficult to reach, one workaround (described in similar lockout cases) is to:
- Create a separate temporary Microsoft 365/Azure trial tenant.
- Sign in to that new tenant’s admin portal.
- From there, open a support request explicitly stating that the issue is with a different existing tenant where the Global Admin is locked out by Conditional Access.
- Provide the locked tenant’s domain, admin UPN, and error details so support can engage the Data Protection team for that tenant.
- This temporary tenant is only for contacting support; it does not give access to the locked tenant’s resources.
- If direct phone support is difficult to reach, one workaround (described in similar lockout cases) is to:
- Future prevention once access is restored
- Configure at least two Global Admin accounts with different credentials and MFA methods.
- Create emergency access (break-glass) accounts that are excluded from all Conditional Access policies, with strong passwords and monitored sign-in activity.
- Avoid blanket Conditional Access policies that apply to all admins; always test policies and ensure break-glass accounts are excluded before enforcing.
These steps align with Microsoft’s documented guidance for Conditional Access lockouts and tenant lockout prevention and rely on Microsoft support/Data Protection to recover a tenant when the sole Global Admin is blocked by Conditional Access.
References:
- Troubleshoot sign-in problems with Conditional Access
- Preventing tenant lockouts
- Plan a Conditional Access deployment
- Require MFA for Azure management
- Require MFA for administrators
- Troubleshoot sign-in issues and account access problems
- Global Admin Locked out - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- I need to reset my mfa methods - Microsoft Q&A
- 7 Day Old Azure Account: AADSTS5000225: This tenant has been blocked due to inactivity. - Microsoft Q&A