URGENT: Global Admin Tenant Lockout - Active MFA Fatigue Attack - Case Escalation to Data Protection Team Required

John Brown 5 Reputation points
2026-04-04T12:26:26.9266667+00:00

Situation Summary: I am the sole Global Administrator for this tenant. My account is currently under a persistent MFA Fatigue / Brute Force attack originating from Russia (receiving 4–5 unauthorized "Approve" requests daily). My password has been compromised, and the attacker has attempted to lead me to phishing sites (PII.in).

The Problem: I am in the process of migrating to a new device (iPhone 17). Due to the high volume of malicious login attempts, my Microsoft Authenticator app on the old device (iPhone 15) is out of sync. Manual 8-digit codes are being rejected with "Unexpected Error" (AADSTS160021), and push notifications for my own legitimate logins are not arriving.

Requested Action: I am completely locked out of the Admin Center and cannot reset my own MFA or Password. I require an immediate callback from the Data Protection Team to:

Verify my identity and domain ownership.

Manually reset/clear my MFA registration.

Revoke all active sessions to kick out the unauthorized attacker.

Contact Info: Please contact me at PII. I am available immediately to perform DNS verification or provide business documentation to prove ownership.

Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Oldest
  1. AI answer

    2026-04-04T12:26:43.19+00:00

    This scenario matches a tenant lockout with no other Global Administrator available and MFA preventing access. Community and documentation guidance indicate that such cases must be handled directly by Microsoft Support/Data Protection; forums and tools like this cannot trigger callbacks, open tickets, or perform identity verification.

    Actions supported by the provided guidance:

    1. If there is any other Global Administrator or a partner with GDAP and the right roles:
      • A Global Administrator or a partner with Privileged Authentication Administrator or equivalent GDAP roles can:
        • Sign in to the Azure portal → Microsoft Entra ID → Users → select the affected account → Authentication methods → select Require re-register multifactor authentication to force MFA re-registration on the new device.
        • Reset the account password if they have the appropriate role, following the guidance in Who can reset passwords for role guidance?.
    2. If there is no other Global Administrator (sole admin locked out):
      • This is treated as a tenant lockout scenario. The guidance in similar cases shows that resolution requires escalation to Microsoft via a support ticket so the Data Protection/Tenant Recovery team can verify ownership and restore access.
      • For business tenants, the documented path is:
        • Use the published Microsoft 365 for business support phone numbers by country or region to contact Microsoft Support directly: Find Microsoft 365 for business support phone numbers by country or region.
        • Clearly state that this is a Global Admin tenant lockout with MFA and there is no other Global Administrator.
        • The support engineer can then engage the Data Protection team to verify tenant ownership (for example via domain/DNS verification and business documentation) and:
          • Reset/clear MFA registration for the locked-out Global Admin.
          • Help restore access to the tenant.
    3. While locked out and under active attack:
      • If repeated sign-in attempts are occurring, Microsoft Entra MFA may temporarily block further attempts as a protection mechanism. Guidance for repeated MFA failures is to wait for the lockout window to expire and, if possible, use a different MFA method. In this case, because no other method is available and the account is under attack, direct admin intervention via Microsoft Support is required.
    4. After access is restored (per documented best practices):
      • Reset the compromised password and ensure it is unique and strong.
      • Re-register MFA on the new device and consider phishing-resistant methods such as passkey (FIDO2) or certificate-based authentication, which satisfy MFA requirements and better resist MFA fatigue attacks.
      • Revoke active sessions using Microsoft Graph or the portal once access is available again, for example with Revoke-MgUserSignInSession -UserId <UPN> after connecting to Microsoft Graph with the appropriate scopes.
      • Implement emergency access (“break-glass”) accounts that are cloud-only Global Administrators, excluded from Conditional Access where appropriate, and monitored via sign-in logs and alerts. This prevents future total lockouts.

    Because tools like this cannot open support tickets or contact the Data Protection team, the only supported path in the provided material for a sole Global Admin locked out by MFA is to contact Microsoft Support directly using the official business support phone numbers so they can escalate to Data Protection/Tenant Recovery.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.