How can I recover my Microsoft admin account for Azure Portal?

Hector Villafuerte 0 Reputation points
2026-04-04T15:44:48.65+00:00

How can I recover my Microsoft admin account? Here’s the situation:

  • I enabled MFA for my admin account to get in azure portal, using only the Microsoft Authenticator app on my Samsung Android.
  • I lost my phone and did not set up a backup for the Authenticator app.
  • I recently recovered my phone, but it has been reset.
  • When I try to log in, it asks for a code from the Authenticator app, which I can’t provide since the app was wiped.
  • The only alternative is to get help from the organization admin-but that’s me, and I can’t access my account.
Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Newest
  1. AI answer

    2026-04-04T15:45:07.55+00:00

    Because the account is protected by MFA and there is no other admin who can reset it, recovery must go through Microsoft support and the Data Protection/Tenant Recovery process.

    Use these options depending on whether there is any other global admin; from the description, there is not.

    1. Confirm there is truly no other global admin
    • If there is another global administrator in the tenant, that admin can reset MFA for the locked account:
      1. That admin signs in to the Azure portal and opens Microsoft Entra ID.
      2. Go to Users and select the locked admin account.
      3. Open Authentication methods.
      4. Select Require re-register multifactor authentication.
      5. Next time the locked admin signs in, Azure will prompt to set up MFA again on the (new) Authenticator app.
    1. If you are the only global admin (sole admin lockout) When there is no other global admin, only Microsoft’s Data Protection team can reset the MFA registration after verifying identity and tenant ownership.

    Follow this path:

    Option 1 – Call Microsoft support and ask for Data Protection / Tenant Recovery

    1. Call the regional Customer service phone numbers - Microsoft Support listed in the documentation.
    2. When navigating the IVR/agent, clearly state:
      • The issue is Authenticator / MFA lockout.
      • The product is Office 365 for business / Azure for a company account.
      • It is a company (work) account, not personal.
      • You are the only global administrator and are locked out because the Microsoft Authenticator app was wiped and no other MFA methods are configured.
      • You need a service request with the Data Protection team to reset MFA for the tenant admin account.
    3. The frontline agent should create a ticket and route it to the Data Protection / Tenant Recovery team.
    4. Be prepared to provide business and identity verification (tenant domain, admin UPN, business details, etc.). Once verified, they can clear/reset MFA so sign-in can be completed and MFA re-registered on the new Authenticator app.

    Option 2 – Create a temporary trial tenant to open a support ticket If phone support cannot be reached or cannot correctly route the case, a workaround is to:

    1. Sign up for a new Microsoft 365 trial tenant (a separate environment) using the public Microsoft 365 Business/Enterprise trial page.
    2. Complete setup and sign in to the Microsoft 365 admin center for this new tenant.
    3. In the new tenant’s admin center, go to Support → Help & support.
    4. Open a support ticket and clearly state:
      • The ticket is about a different, existing tenant where you are the global admin.
      • You are locked out due to MFA (Microsoft Authenticator) and are the only admin.
      • Provide the locked tenant’s domain, admin sign-in name, and error behavior.
      • Request escalation to the Data Protection team to reset MFA for the original tenant.
    5. Work with support until the Data Protection team verifies ownership and resets MFA on the locked tenant.
    6. After recovery, cancel the trial tenant subscription to avoid charges.
    7. After Microsoft resets MFA Once Data Protection or another admin has cleared MFA:
    8. Sign in again with the admin username and password.
    9. When prompted, re-register MFA on the recovered/new phone:
      • Install Microsoft Authenticator.
      • Add the work account using the QR code or sign-in flow presented.
    10. Add at least one backup method (e.g., SMS, office phone, or another app/device) so a single-device loss does not cause another lockout.

    This scenario cannot be resolved self-service when there is only one global admin and no alternative MFA methods; Microsoft support/Data Protection involvement is required.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.