A cloud-based identity and access management service for securing user authentication and resource access
The issue is a sign-in and device/MFA problem that cannot be fixed by the v‑dash contractor directly and requires action by a tenant administrator or Microsoft’s Data Protection/support team.
From the provided context, similar lockout scenarios (lost/changed phone, no access to Authenticator, no alternative method, or only one/global admin) are resolved only by:
- Having a tenant admin reset MFA / require re-registration
- An admin in Microsoft Entra ID must:
- Go to Microsoft Entra admin center (https://entra.microsoft.com).
- Navigate to Users → All users → [select the user] → Authentication methods.
- Select Require re-register multifactor authentication so that MFA methods and device bindings can be set up again at next sign-in.
- This pattern is described in the moderator guidance for resetting MFA methods and re-registering authentication options.
- An admin in Microsoft Entra ID must:
- If no accessible admin/helpdesk exists, engaging Microsoft support / Data Protection team
- For business/organization accounts where the user is locked out and there is no other admin who can reset MFA or device trust, the documented path is to open a support ticket and have the Microsoft Data Protection team intervene.
- In similar cases (for example, a single global admin locked out, or a phone number blocked for MFA), moderators indicate that Microsoft support/Data Protection can:
- Reset MFA.
- Clear problematic flags.
- Restore access so that sign-in and MFA/device registration can be completed again.
- The escalation is initiated via the regional customer service phone numbers listed in the documentation. Frontline support then raises a ticket to the Data Protection team.
- Use sign-in logs and Entra sign-in diagnostics (for admins investigating)
- An Entra admin can review Microsoft Entra sign-in events to see why Conditional Access or device trust is blocking the sign-in, including device details and policy evaluation.
- If policies are misconfigured (for example, requiring a compliant or domain-joined device that the contractor cannot provide), the admin must adjust Conditional Access or device requirements accordingly.
Given the constraints in the question (no campus access, no sponsor, no internal admin/help desk), the only supported resolution path in the context is:
- Identify or reach the organization’s Microsoft 365/Entra administrator (for example, via the company’s internal process or the “find my admin” guidance referenced in similar cases) and have them reset MFA and device bindings as above; or
- If that is not possible, open a support case with Microsoft using the published customer service phone numbers so that the Data Protection team can verify identity and reset access (MFA/device trust) on the tenant side.
The context does not provide a self-service method for a v‑dash contractor to bypass Conditional Access or register a trusted device without admin or Microsoft support involvement.
References:
- Common problems with two-step verification for a work or school account
- Troubleshoot sign-in problems with Conditional Access
- Error AADSTS530004 - AcceptCompliantDevice setting isn't configured for this organization
- I need to reset my mfa methods - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- Azure has blocked myphone number for SMS verification due to a “bad reputation” flag - Microsoft Q&A