A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Because the account is protected by MFA with Microsoft Authenticator as the only method and there is no other Global Administrator, this is a tenant lockout scenario that cannot be resolved by self-service.
Use the following recovery paths:
- If there is any other Global Administrator (even if not remembered initially):
- That admin must sign in to the Azure/Microsoft Entra admin center.
- Go to Microsoft Entra ID → Users → [locked-out admin account] → Authentication methods.
- Select Require re-register multifactor authentication.
- Next time a sign-in is attempted, the account will be prompted to set up MFA again on the new phone.
(This is the standard resolution when another Global Admin exists.)
- If there is truly no other Global Administrator (sole admin / full tenant lockout):
This requires Microsoft’s Data Protection / Tenant Recovery process. Option A – Call Microsoft Support (recommended):- Call the regional Microsoft customer service number listed under Customer service phone numbers - Microsoft Support.
- In the IVR or with the agent, clearly state:
- The issue is with Microsoft Authenticator / MFA.
- The product is Office 365 / Microsoft 365 for business.
- It is a company/work account, not personal.
- Confirm being the only administrator and that the tenant is locked out due to MFA on the admin account.
- Request creation of a service request with the Data Protection team (tenant admin MFA reset / tenant recovery).
- The Data Protection team will verify identity and ownership and can reset the admin’s MFA registration so new methods can be configured.
- Sign up for a new Microsoft 365 trial tenant (separate from the locked tenant).
- In the new tenant, go to the Microsoft 365 Admin Center → Support → Help & support.
- Open a support ticket explaining:
- Being locked out of a different, existing Microsoft 365 tenant.
- The admin UPN and domain of the locked tenant.
- That MFA is enforced, Authenticator is unavailable, and there are no other admins.
- Request escalation to the Data Protection team for tenant admin MFA reset / recovery.
- This trial tenant is only a channel to reach support; it does not give access to the locked tenant’s data.
In all sole-admin lockout cases, only Microsoft Support (Data Protection) can reset or clear the MFA requirement so that authentication methods can be re-registered on the new device.
References:
- Troubleshoot problems with Microsoft Authenticator
- Preventing tenant lockouts
- Mandatory multifactor authentication for Azure and admin portals
- Global Admin Locked out - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- I need to reset my mfa methods - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Authenticator Did Not Complete Login
- Common problems with two-step verification for a work or school account