no access as cellphone with authenticator app resteted

Anonymous
2026-03-31T15:42:37.96+00:00

Hi,

I have a new cellphone and I missed to connect the Authenticator app on the new one before the old one was deleted.

As I'm the admin no one else can access the account

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Oldest
  1. AI answer

    2026-03-31T15:42:50.0466667+00:00

    Because the only admin account is locked behind Microsoft Authenticator on a phone that was reset, this is a tenant lockout scenario that cannot be fixed self‑service. Recovery must go through Microsoft support and the Data Protection team.

    Use these steps:

    1. Contact Microsoft support by phone and request Data Protection team
      • Call the appropriate number from Customer service phone numbers - Microsoft Support (commercial support line).
      • When the IVR/agent asks about the issue, clearly state that:
        • This is an Authenticator / MFA problem.
        • The product is Office 365/Microsoft 365 for business.
        • It is a company/work account.
        • The caller is the only global admin and is locked out because the phone with Microsoft Authenticator was reset.
        • A service request is needed and it must be escalated to the Data Protection team to reset MFA for the tenant admin.
      • Be prepared to provide tenant details (admin sign‑in name, domain, business details, contact info) and complete identity verification. The Data Protection engineers will then work with the caller to reset/re‑register MFA and add an additional auth method.
    2. If phone support cannot be reached, create a temporary trial tenant to open a ticket
      • Sign up for a new Microsoft 365 trial tenant (separate from the locked one).
      • In the new tenant, go to the Microsoft 365 admin center → Support → Help & support.
      • Open a support ticket explaining:
        • The ticket is about a different existing tenant where the only global admin is locked out due to Microsoft Authenticator on a reset phone.
        • Include the locked tenant’s domain, admin UPN, and error behavior (MFA loop, no access to Authenticator).
        • Request escalation to the Data Protection team to reset MFA for the original tenant’s admin.
      • After the original tenant is recovered, cancel the trial subscription for the temporary tenant to avoid charges.

    Once the Data Protection team verifies identity, they can reset MFA on the admin account so a new phone and new authentication methods can be configured.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.