A cloud-based identity and access management service for securing user authentication and resource access
Because the Conditional Access policy is blocking all admins, including break-glass accounts, the policy can’t be fixed from within the tenant and must be remediated by Microsoft support.
Follow these steps to get the policy corrected by the Data Protection / support team:
- Check for any remaining unblocked admin
- If there is any administrator who can still sign in, that admin should immediately disable or modify the problematic Conditional Access policy.
- Guidance: “If you're locked out because of an incorrect setting in a Conditional Access policy: 1. Check if there are other admins in your organization who aren't blocked yet. An admin with access can disable the policy that's affecting your sign-in.”
- If no admin can access the tenant
- When all admins (including break-glass accounts) are blocked, Microsoft support must intervene.
- Open a support request specifically for Conditional Access lockout and request that Microsoft update or disable the CA policy that is preventing access.
- Use the official support channel: see How to get support (linked in the Conditional Access troubleshooting article).
- From the support request, clearly state:
- That this is a Conditional Access lockout scenario.
- That the policy applies to All users, including emergency/break-glass accounts.
- That no admin account can sign in to Entra ID / Azure portal to change the policy.
Microsoft support (including the Data Protection team when appropriate) will review and, after confirming the lockout, update the Conditional Access policies that prevent access.
For future prevention, ensure that at least two emergency access accounts are excluded from all Conditional Access policies and tested before enforcing new policies, as described in the tenant lockout prevention guidance.
References: