Urgent: Global Admin Locked Out of Tenant Due to Conditional Access Policy

Slavko 0 Reputation points
2026-03-31T08:11:24.51+00:00

Hello everyone,

I urgently need assistance.

I have accidentally locked myself out of my Microsoft Entra ID (Azure AD) tenant due to a Conditional Access policy. The issue occurred because the Global Administrator account was mistakenly removed from the exclusion list of the policy.

As a result, I currently have no administrative access to the tenant. There are no break-glass accounts configured, and no other admin is able to access the environment.

I would urgently require guidance or support on how to proceed, especially regarding possible intervention from Microsoft to disable or bypass the Conditional Access policy.

I can provide any additional information needed to verify ownership or assist with the resolution.

Thank you in advance for your help.

Microsoft Security | Microsoft Entra | Other
0 comments No comments

1 answer

Sort by: Newest
  1. AI answer

    2026-03-31T08:11:41.7133333+00:00

    Proceed as follows to recover access when locked out by a Conditional Access policy and no other admins or break-glass accounts are available:

    1. Confirm there is truly no other admin able to sign in
      • If any other administrator account (Global Administrator, Privileged Role Administrator, Conditional Access Administrator, etc.) can still sign in, that admin should disable or modify the Conditional Access policy that is blocking access.
      • Guidance: “If you're locked out because of an incorrect setting in a Conditional Access policy: Check if there are other admins in your organization who aren't blocked yet. An admin with access can disable the policy that's affecting your sign-in.”
    2. If no admin can sign in, contact Microsoft Support for tenant recovery
      • When all admins are blocked, Microsoft Support can intervene after verifying ownership of the tenant.
      • The documented path is: “If no admin in your organization can update the policy, submit a support request. Microsoft support reviews and, after confirming, updates the Conditional Access policies that prevent access.”
      • Use the appropriate Microsoft support channel (phone or support request) for your region and subscription to open a Data Protection / Tenant Recovery case. Clearly state:
        • All admin accounts are blocked by a Conditional Access policy.
        • There are no emergency access (break-glass) accounts.
        • You need Microsoft to adjust or disable the blocking Conditional Access policy.
    3. After access is restored, create and exclude emergency access accounts
      • To prevent future lockouts, create at least two emergency access (“break-glass”) accounts with Global Administrator role as described in the emergency access guidance.
      • These accounts should:
        • Be used only for emergencies.
        • Be excluded from all Conditional Access policies.
      • Multiple Microsoft docs explicitly recommend excluding:
        • Emergency access / break-glass accounts from Conditional Access policies.
    4. Review and correct Conditional Access design
      • Once access is restored, review all Conditional Access policies to ensure:
        • At least one or more emergency access accounts are excluded.
        • Service accounts and service principals are handled appropriately using Conditional Access for workload identities where needed.

    This scenario cannot be resolved purely by self-service if no administrator can sign in; Microsoft Support intervention is required to modify or disable the blocking Conditional Access policy after verifying tenant ownership.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.