Global Admin Locked Out – MFA / Authenticator Loop

Akhil Shukla 0 Reputation points
2026-04-04T03:51:15.0166667+00:00

Hello Microsoft Support,

I am currently completely locked out of my account due to a Microsoft Authenticator issue.

Situation:

  • I recently changed my phone (iPhone 14 → iPhone 17)
  • The Microsoft Authenticator app was not transferred
  • My account requires MFA via Authenticator
  • I have my correct password, but every login attempt asks for an Authenticator code
  • I have no alternative verification methods configured (no SMS/email backup)
  • I am the only Global Admin, so I cannot reset MFA myself

This has resulted in a full admin lockout, and I am unable to access:

  • Microsoft 365 Admin Center
  • Entra / Azure portal
  • Support channels (as they also require login)Hello Microsoft Support

Request: Please assist with:

  • Resetting MFA for my admin account OR
  • Enabling re-registration of authentication methods
Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-04-04T03:51:29.03+00:00

    Because the account is protected by MFA with Microsoft Authenticator as the only method and there is no other Global Administrator, this is a tenant lockout scenario that cannot be resolved by self-service.

    Use the following recovery paths:

    1. If there is any other Global Administrator (even if not remembered initially):
      • That admin must sign in to the Azure/Microsoft Entra admin center.
      • Go to Microsoft Entra ID → Users → [locked-out admin account] → Authentication methods.
      • Select Require re-register multifactor authentication.
      • Next time a sign-in is attempted, the account will be prompted to set up MFA again on the new phone.
        (This is the standard resolution when another Global Admin exists.)
    2. If there is truly no other Global Administrator (sole admin / full tenant lockout):
      This requires Microsoft’s Data Protection / Tenant Recovery process. Option A – Call Microsoft Support (recommended):
      • Call the regional Microsoft customer service number listed under Customer service phone numbers - Microsoft Support.
      • In the IVR or with the agent, clearly state:
        • The issue is with Microsoft Authenticator / MFA.
        • The product is Office 365 / Microsoft 365 for business.
        • It is a company/work account, not personal.
        • Confirm being the only administrator and that the tenant is locked out due to MFA on the admin account.
        • Request creation of a service request with the Data Protection team (tenant admin MFA reset / tenant recovery).
      • The Data Protection team will verify identity and ownership and can reset the admin’s MFA registration so new methods can be configured.
      Option B – Create a temporary trial tenant to open a ticket (if phone support fails):
      • Sign up for a new Microsoft 365 trial tenant (separate from the locked tenant).
      • In the new tenant, go to the Microsoft 365 Admin Center → Support → Help & support.
      • Open a support ticket explaining:
        • Being locked out of a different, existing Microsoft 365 tenant.
        • The admin UPN and domain of the locked tenant.
        • That MFA is enforced, Authenticator is unavailable, and there are no other admins.
        • Request escalation to the Data Protection team for tenant admin MFA reset / recovery.
      • This trial tenant is only a channel to reach support; it does not give access to the locked tenant’s data.

    In all sole-admin lockout cases, only Microsoft Support (Data Protection) can reset or clear the MFA requirement so that authentication methods can be re-registered on the new device.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.