Additional Microsoft Entra services and features related to identity, access, and network security
- Yes, access can be recovered, but only with Microsoft support involvement when there is no other Global Administrator and self-service options (password reset, MFA registration) are unavailable. This is treated as a tenant lockout scenario and is handled by the Microsoft Data Protection / Tenant Recovery team. The documentation on tenant lockouts states that when all Global Admins lose access (for example, due to MFA issues), Microsoft must work directly with a Global Administrator on the affected tenant to restore access. When self-service recovery and partner assistance are not possible, the Data Protection team uses internal tools and verification processes to help regain access to the administrator account and reset MFA or password as needed.
- To contact Microsoft support without being able to sign in, use the phone channel for business support and explicitly request the Data Protection (or Microsoft 365/Azure Data Protection) team:
- Use the regional phone numbers listed under business support (for example, “Get support – Microsoft 365 admin” / “Support for Business Products”).
- When the automated system asks for the issue, clearly state “Authenticator” or “sign-in / MFA lockout” and that this is for a company/organization account.
- When asked whether this is an admin issue, answer that it is, and that there is no other Global Administrator on the tenant.
- Ask the frontline agent to open a service request and route it to the Data Protection team for tenant lockout / admin account recovery.
- For proving ownership of the tenant, the Data Protection team will require information that demonstrates administrative control and legitimate association with the organization. While the exact verification flow is handled case-by-case, the documentation and Q&A patterns indicate that you should be prepared with:
- The administrator account UPN/email address for the locked tenant.
- The tenant’s primary domain name.
- Confirmation that you are (or were) the Global Administrator and that there are no other Global Admins available.
- Business/organization details that match the tenant records (for example, company name, address, billing or subscription details, and other documentation proving that the organization controls the tenant’s domains and subscriptions).
- Any error messages you receive when attempting to sign in (for example, MFA prompts, lockout messages), including timestamps and correlation IDs if available.
Going forward, once access is recovered, it is important to:
- Configure at least two Global Administrator accounts with distinct credentials and MFA methods.
- Create emergency “break-glass” accounts that are protected with strong authentication and documented for recovery scenarios.
- Enable and test Self-Service Password Reset (SSPR) and keep recovery methods up to date.
- Ensure MFA is configured using resilient methods such as passkey (FIDO2) or certificate-based authentication, which satisfy mandatory MFA requirements.
References:
- Troubleshoot sign-in issues and account access problems
- Preventing tenant lockouts
- Mandatory multifactor authentication for Azure and admin portals
- Global Admin Locked out - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- I need to reset my mfa methods - Microsoft Q&A
- Azure has blocked myphone number for SMS verification due to a “bad reputation” flag - Microsoft Q&A