A cloud-based identity and access management service for securing user authentication and resource access
The 16‑digit code from Microsoft Support is not entered on the normal MFA prompt screen. The standard sign‑in page for a Global Admin will still only show the existing MFA methods (Authenticator push or 6‑digit OTP), so there is no field there for a 16‑digit recovery code.
For a sole Global Administrator who is locked out because of Microsoft Authenticator and has no alternative MFA method, the path to regain access is through Microsoft’s Data Protection / Tenant Recovery process, not through the regular sign‑in UI:
- Call Microsoft’s global customer service phone number for business support.
- Clearly state that this is a tenant‑admin lockout, that this is an E5 commercial tenant, and that there is no other Global Admin.
- Ask to open a service request and be routed to the Data Protection team (sometimes called Tenant Recovery/Data Protection).
- Follow their identity‑verification process; they will use the 16‑digit code and other information as part of that process and then reset the MFA registration on the Global Admin account from the backend.
- After the reset is completed by the Data Protection team, sign in again with username and password; the portal will then prompt to register MFA from scratch (new Authenticator app, phone, etc.).
The 16‑digit code is used by Microsoft Support/Data Protection internally to validate and process the case; it is not something that can be typed into the normal 6‑digit MFA field or the Authenticator app.
References: