A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Because the account is a Microsoft 365 global admin account and access to the previous 2FA device is lost, the 2FA/MFA methods must be reset by an administrator or by Microsoft support, depending on whether there are other admins in the tenant.
Use the following options based on the tenant setup:
- If there is another global admin in the tenant
- Another global admin can reset the MFA settings so the admin account can re-register 2FA:
- Sign in to the Microsoft Entra admin center as a global admin.
- Go to Users → All users and select the locked-out admin account.
- Open Authentication methods.
- Choose Require re-register multifactor authentication.
- Save the changes.
- After this, sign in again; the account will be prompted to set up MFA (e.g., Microsoft Authenticator on the new phone) from scratch.
- Another global admin can reset the MFA settings so the admin account can re-register 2FA:
- If there is no other global admin (only one admin on the tenant)
- This is a tenant lockout scenario. Only Microsoft’s Data Protection team can restore access:
- Call Microsoft’s global customer service/support and request a Data Protection case for an admin locked out by MFA. Use the phone flow described in the context:
- When the IVR asks what the problem is, answer: Authenticator.
- Product: Office 365 for business.
- Account type: Company (not education/personal).
- Confirm: Yes, this is an administrator account.
- Confirm: No, there are no other admins.
- Request to create a service request and be routed to the Data Protection team to reset the admin’s MFA.
- Be prepared to provide tenant details (admin UPN, tenant domain, subscription info, business documentation) so Microsoft can verify identity and ownership before resetting MFA.
- If support is hard to reach (fallback method)
- Create a temporary trial Microsoft 365 tenant only as a channel to open a support ticket:
- Sign up for a Microsoft 365 trial and complete tenant creation.
- In the new tenant, go to the Microsoft 365 admin center → Support → Help & support.
- Open a ticket explaining that the real problem is a different existing tenant where the global admin is locked out by MFA and is the only admin.
- Ask to be connected to the Data Protection team for that original tenant.
- After the original tenant issue is resolved, cancel the trial subscription on the temporary tenant to avoid charges.
- Create a temporary trial Microsoft 365 tenant only as a channel to open a support ticket:
Once Microsoft or another admin resets MFA, sign in again and register new 2FA methods on the new phone (for example, Microsoft Authenticator plus a phone number as backup) so that future device changes do not cause lockout.
References:
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- I need to reset my mfa methods - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- Can't use Azure Multi-Factor Authentication to sign in to cloud services after you lose your phone or the phone number changes
- Common problems with two-step verification for a work or school account