A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
For an Azure account lockout combined with ongoing billing, the fastest resolution path is through Microsoft support channels that can both (1) restore access (via Data Protection / tenant recovery) and (2) address subscription/billing.
- To regain access when locked out by MFA
Because MFA is blocking sign-in and there is no working second method, self-service recovery is not possible. When there is no other global admin who can reset MFA, the case must be escalated to the Data Protection / Tenant Recovery team via a support ticket. This is the same pattern used in similar tenant-lockout cases:
- A support ticket is opened.
- The case is escalated to a duty manager / Data Protection team.
- The Data Protection engineer verifies identity and ownership using documentation and contact details.
- After verification, the engineer resets or re-registers MFA for at least one admin account so portal access can be restored.
If there is any other global admin on the tenant, that admin can immediately fix the MFA lockout by:
- Signing in to the Azure portal.
- Going to Microsoft Entra ID → Users.
- Selecting the locked-out user.
- Opening Authentication methods and choosing Require re-register multifactor authentication.
- The next sign-in for that user will prompt for MFA registration again.
If there is no other global admin, the only supported path is escalation via support so the Data Protection team can reset MFA after verifying ownership.
- To stop ongoing Azure charges and resolve billing
Billing and subscription issues (including past-due or unwanted charges) are handled through Azure billing support:
- If the subscription is still active and accessible once account access is restored, cancel it from the Azure portal so future charges stop.
- If access cannot be restored yet but charges continue, open a billing/support request so an agent can review the subscription state and charges and help resolve them.
For pay-as-you-go Azure subscriptions with past-due or disputed charges, the documented path is to contact Azure support using a support request. Support can review:
- Whether the subscription is still active or disabled.
- Any past-due balance and what happens to resources and data.
- Next steps to resolve the balance or stop further billing.
- Practical next steps
- Open a support request specifically for account access / tenant lockout and clearly state:
- Locked out due to MFA with no working method.
- Only admin on the tenant (if true).
- Ongoing billing on the credit card.
- Request escalation to Data Protection / Tenant Recovery to reset MFA and restore access.
- In parallel or after access is restored, open or update a billing support request to:
- Cancel the active Azure subscription so future charges stop.
- Review recent charges and any past-due balance.
- Provide all requested identity and ownership documentation promptly so the Data Protection team can complete verification and perform the MFA reset.
Once MFA is reset and portal access is restored, immediately:
- Sign in to the Azure portal.
- Cancel any subscriptions that should no longer be billed.
- Add multiple MFA methods (e.g., Authenticator plus phone) and, if applicable, another global admin to avoid future lockouts.
References:
- Resolve a past-due balance for your pay-as-you-go Azure subscription
- Which support portal should I use?
- How Do I Regain Access to My Account After Losing Access to Microsoft Authenticator? (Urgent Request). - Microsoft Q&A
- Global Admin Locked out - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A