Global Admin locked out – MFA reset needed (tenant PII)

marcello guastella 0 Reputation points
2026-04-03T16:58:35.9466667+00:00

I am the only Global Administrator of tenant unifysystem.it

(admin account:PII).

I am completely locked out due to MFA issues:

  • Microsoft Authenticator app was removed from device
  • No backup MFA methods available
  • Password has been reset successfully via alternate email
  • MFA is still required to complete login (Error Code: 500121)

I need escalation to the Microsoft 365 Data Protection Team

for an admin MFA reset / tenant recovery.

I can verify domain ownership via DNS TXT record on unifysystem.it.

Tenant details:

  • Domain: PII
  • Locked admin UPN: PII
  • Error Code: 500121

Please assist urgently.

Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Most helpful
  1. AI answer

    2026-04-03T16:58:53.3966667+00:00

    For a single Global Administrator who is fully locked out due to MFA (error 500121) with no alternative methods, the only supported path is recovery through Microsoft support and the Data Protection / Tenant Recovery process. Community moderators and forums cannot directly reset MFA or access the tenant.

    Follow these steps:

    1. Contact Microsoft support by phone
      • Call Microsoft Global Customer Service for business: use the numbers listed under Customer service phone numbers - Microsoft Support.
      • Clearly state during the IVR and to the agent:
        • This is an Office 365 / Microsoft 365 for business tenant.
        • It is a company (work) account, not personal.
        • The caller is the only Global Administrator for the tenant unifysystem.it.
        • The issue is a tenant lockout due to MFA (Microsoft Authenticator removed, no backup methods, error code 500121).
        • A Data Protection / Tenant Recovery case is needed to reset the admin’s MFA methods.
      Example flow (from existing guidance):
      • When asked what the problem is: say “Authenticator”.
      • Product: “Office 365 for business”.
      • Account type: “For companies”.
      • Are you an administrator? “Yes.”
      • Do you have another administrator? “No.”
      • When asked if a service request is needed: “Yes, I need to create a ticket and speak with the Data Protection team.”
    2. Prepare verification information The Data Protection team will require proof of ownership/administrative control. Be ready to provide, as requested:
      • Domain ownership proof (for example, adding a DNS TXT record on unifysystem.it).
      • Official business documentation (registration, tax or company documents matching the tenant organization name).
      • Contact details that match public or tenant records.
    3. If phone support is hard to reach
      • As an alternative, create a temporary trial tenant (for example, a Microsoft 365 Business trial) and use that new tenant’s admin center to open a support ticket.
      • In the ticket, clearly state that the request is on behalf of the existing tenant unifysystem.it, that the only Global Admin is locked out due to MFA, and that a Data Protection / Tenant Recovery escalation is required.
    4. What Microsoft for Nonprofits or partners can and cannot do (if applicable)
      • If a partner manages the tenant and has GDAP with the Privileged Authentication Administrator role, they can reset MFA and password directly.
      • If no such partner access exists, or no one can sign in with sufficient rights, Microsoft must work directly with the tenant’s Global Admin through the Data Protection process.

    Until Microsoft completes identity verification and resets the MFA methods, access to the tenant cannot be restored by any self-service or community mechanism.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.