A cloud-based identity and access management service for securing user authentication and resource access
Because the tenant has only one Global Administrator and that admin is locked out due to MFA with no backup methods, this is a tenant lockout scenario that cannot be fixed from the admin portals and must be handled by Microsoft’s Data Protection/Tenant Recovery support.
Use these supported options:
- Call Microsoft support and ask for the Data Protection team
- Use the regional phone number listed under Customer service phone numbers - Microsoft Support or Find Microsoft 365 for business support phone numbers by country or region.
- When connected to the IVR/agent, clearly state:
- This is a business / Microsoft 365 for business / Microsoft Entra ID account.
- There is only one Global Administrator on the tenant.
- That Global Admin is locked out due to MFA (Authenticator removed / new phone, no backup methods).
- A Data Protection / Tenant Recovery case is needed to reset MFA / security info for the Global Admin.
- If the IVR is conversational, use prompts similar to those documented:
- Problem type: “Authenticator” or “Multi-factor authentication”
- Product: “Office 365 for business” or “Microsoft 365 for business”
- Account type: “Company account”
- Are you an administrator?: “Yes”
- Do you have another administrator?: “No”
- Request: “Yes, I need to create a ticket and speak with the Data Protection team.”
- If direct phone routing fails, open a support ticket via a temporary tenant
- Create a new Microsoft 365 business trial tenant (as described in the Q&A guidance).
- From that new tenant’s Microsoft 365 admin center, open a support request and explicitly ask to be connected to the Data Protection team for the original (locked) tenant.
- In the ticket, include:
- The locked tenant’s primary domain / tenant ID.
- That there is only one Global Admin and they are blocked at MFA.
- A request to reset MFA / authentication methods for that Global Admin.
- If the tenant is partner-managed (CSP/GDAP)
- If a Cloud Solution Provider partner or another partner has GDAP with Privileged Authentication Administrator or Global Administrator on the tenant, they can reset MFA or require re-registration directly and there is no need to contact Microsoft.
- If the partner has GDAP but not the required password/MFA roles, the end-customer Global Administrator (in this case, the locked-out admin) must still work with Microsoft support as above.
- Future prevention once access is restored
- Ensure the tenant has at least two Global Admin accounts with different MFA methods.
- Create break-glass emergency accounts excluded from Conditional Access and with strong passwords, and monitor their sign-ins.
- Configure additional MFA methods (e.g., phone, passkey/FIDO2, certificate-based auth) and enable Self-Service Password Reset (SSPR) where appropriate.
Forum moderators and community responders cannot reset MFA or access for tenant admins; only Microsoft’s Data Protection/Tenant Recovery process or a partner with the correct GDAP roles can resolve this scenario.
References:
- Troubleshoot sign-in issues and account access problems
- Preventing tenant lockouts
- Tenant Lockout: Scenarios & Next Steps
- About administrator roles in the Microsoft 365 admin center
- Common problems with two-step verification for a work or school account
- All about passwords
- Mandatory multifactor authentication for Azure and admin portals
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- Global Admin Locked out - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- I need to reset my mfa methods - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A