Additional Microsoft Entra services and features related to identity, access, and network security
Proceed as follows to recover access when locked out by a Conditional Access policy and no other admins or break-glass accounts are available:
- Confirm there is truly no other admin able to sign in
- If any other administrator account (Global Administrator, Privileged Role Administrator, Conditional Access Administrator, etc.) can still sign in, that admin should disable or modify the Conditional Access policy that is blocking access.
- Guidance: “If you're locked out because of an incorrect setting in a Conditional Access policy: Check if there are other admins in your organization who aren't blocked yet. An admin with access can disable the policy that's affecting your sign-in.”
- If no admin can sign in, contact Microsoft Support for tenant recovery
- When all admins are blocked, Microsoft Support can intervene after verifying ownership of the tenant.
- The documented path is: “If no admin in your organization can update the policy, submit a support request. Microsoft support reviews and, after confirming, updates the Conditional Access policies that prevent access.”
- Use the appropriate Microsoft support channel (phone or support request) for your region and subscription to open a Data Protection / Tenant Recovery case. Clearly state:
- All admin accounts are blocked by a Conditional Access policy.
- There are no emergency access (break-glass) accounts.
- You need Microsoft to adjust or disable the blocking Conditional Access policy.
- After access is restored, create and exclude emergency access accounts
- To prevent future lockouts, create at least two emergency access (“break-glass”) accounts with Global Administrator role as described in the emergency access guidance.
- These accounts should:
- Be used only for emergencies.
- Be excluded from all Conditional Access policies.
- Multiple Microsoft docs explicitly recommend excluding:
- Emergency access / break-glass accounts from Conditional Access policies.
- Review and correct Conditional Access design
- Once access is restored, review all Conditional Access policies to ensure:
- At least one or more emergency access accounts are excluded.
- Service accounts and service principals are handled appropriately using Conditional Access for workload identities where needed.
- Once access is restored, review all Conditional Access policies to ensure:
This scenario cannot be resolved purely by self-service if no administrator can sign in; Microsoft Support intervention is required to modify or disable the blocking Conditional Access policy after verifying tenant ownership.
References:
- Troubleshoot sign-in problems with Conditional Access
- Manage emergency access accounts in Microsoft Entra ID
- Require multifactor authentication for admins accessing Microsoft admin portals
- Require MFA for Azure management
- Protect AI with Conditional Access policy
- Enable compliant network check with Conditional Access
- Apply Conditional Access policies to Global Secure Access internet traffic
- Apply Conditional Access policies to Private Access apps
- Global Admin Locked out - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- 7 Day Old Azure Account: AADSTS5000225: This tenant has been blocked due to inactivity. - Microsoft Q&A
- account unavilable - Microsoft Q&A