Locked out of Azure tenant due to MFA requirement – only Global Admin

Developpeur Audace 0 Reputation points
2026-04-03T14:09:22.5766667+00:00

Hello,

I am currently locked out of my Azure tenant on Microsoft Azure because I did not configure Multi-Factor Authentication (MFA) before the enforcement deadline (October 1, 2025).

I am the only Global Administrator of this tenant, and I now cannot sign in at all (Azure Portal access is completely blocked).

I have already tried:

  • Signing in via the Azure portal
  • Resetting my password
  • Accessing support through Azure

Additionally, I tried contacting Microsoft support by phone to reach the Data Protection team, but I was unable to get through. The automated system keeps redirecting me to online support links (often Azure support pages) where I am required to sign in — which I cannot do.

My questions are:

  1. Is there any way to recover access to the tenant in this situation?
  2. How can I contact Microsoft support without being able to sign in?
  3. What information will be required to prove ownership of the tenant?

Any help or guidance would be greatly appreciated.

Thank you.

User's image

Microsoft Security | Microsoft Entra | Other
0 comments No comments

1 answer

Sort by: Oldest
  1. AI answer

    2026-04-03T14:09:55.55+00:00
    1. Yes, access can be recovered, but only with Microsoft support involvement when there is no other Global Administrator and self-service options (password reset, MFA registration) are unavailable. This is treated as a tenant lockout scenario and is handled by the Microsoft Data Protection / Tenant Recovery team. The documentation on tenant lockouts states that when all Global Admins lose access (for example, due to MFA issues), Microsoft must work directly with a Global Administrator on the affected tenant to restore access. When self-service recovery and partner assistance are not possible, the Data Protection team uses internal tools and verification processes to help regain access to the administrator account and reset MFA or password as needed.
    2. To contact Microsoft support without being able to sign in, use the phone channel for business support and explicitly request the Data Protection (or Microsoft 365/Azure Data Protection) team:
      • Use the regional phone numbers listed under business support (for example, “Get support – Microsoft 365 admin” / “Support for Business Products”).
      • When the automated system asks for the issue, clearly state “Authenticator” or “sign-in / MFA lockout” and that this is for a company/organization account.
      • When asked whether this is an admin issue, answer that it is, and that there is no other Global Administrator on the tenant.
      • Ask the frontline agent to open a service request and route it to the Data Protection team for tenant lockout / admin account recovery.
      If the tenant was obtained through a CSP partner or reseller and you cannot get through directly, the partner can open a support ticket on your behalf using their granular delegated admin privileges (GDAP). If you have a CSP Indirect provider, they can also create a new global admin or reset the password for you if they hold the appropriate GDAP roles.
    3. For proving ownership of the tenant, the Data Protection team will require information that demonstrates administrative control and legitimate association with the organization. While the exact verification flow is handled case-by-case, the documentation and Q&A patterns indicate that you should be prepared with:
      • The administrator account UPN/email address for the locked tenant.
      • The tenant’s primary domain name.
      • Confirmation that you are (or were) the Global Administrator and that there are no other Global Admins available.
      • Business/organization details that match the tenant records (for example, company name, address, billing or subscription details, and other documentation proving that the organization controls the tenant’s domains and subscriptions).
      • Any error messages you receive when attempting to sign in (for example, MFA prompts, lockout messages), including timestamps and correlation IDs if available.
      The Data Protection team will guide through their verification steps and, once satisfied, can reset the admin’s password and/or MFA registration so that sign-in to the tenant is restored.

    Going forward, once access is recovered, it is important to:

    • Configure at least two Global Administrator accounts with distinct credentials and MFA methods.
    • Create emergency “break-glass” accounts that are protected with strong authentication and documented for recovery scenarios.
    • Enable and test Self-Service Password Reset (SSPR) and keep recovery methods up to date.
    • Ensure MFA is configured using resilient methods such as passkey (FIDO2) or certificate-based authentication, which satisfy mandatory MFA requirements.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.