[Microsoft Partner Center] Steps to remove user access restrictions

臼井 秀之 0 Reputation points
2026-04-06T05:36:43.1433333+00:00

[Problem to be solved]

An issue occurred in the Microsoft Partner Center where access to the global administrator account was restricted. (Only one global administrator account was created.)

[Situation]

We have been performing driver code signing at the Microsoft Partners Center.

However, the account authentication process failed, and the application was rejected.

We contacted support to resolve this, but

as time passed without receiving the desired solution, we have ended up in this situation.

[Desired Answer]

I don't know where to start.

Please tell me the minimum necessary steps I should take to resolve the problem.

Microsoft Partner Center | Other

1 answer

Sort by: Newest
  1. AI answer

    2026-04-06T05:36:57.19+00:00

    Follow these steps in order, starting from what can be done immediately, then escalating if needed.

    1. Check if access is blocked by Conditional Access
    • If the message shown in Partner Center is similar to “Access restricted due to conditional access policy”, the restriction is coming from Microsoft Entra (Azure AD) policies, not from Partner Center itself.
    • On the sign-in error page, review the details to see why access is blocked (for example, device not compliant, location blocked, outdated software).
    • If the message indicates something that can be fixed on the device (such as OS/browser/security update), update the device/software and sign in again.
    • If the restriction is not self-fixable, contact the organization’s Azure/Microsoft Entra administrator (if this global admin account is not also the Entra admin) and ask them to review and adjust the Conditional Access policy that is blocking Partner Center access. Partner Center only enforces those policies and cannot override them.
    1. If the tenant is effectively locked out (no one can fix Conditional Access) If Conditional Access or other security configuration is preventing access for the only global administrator and there is no other admin who can sign in:
    • Treat this as a tenant lockout scenario.
    • The end-customer (tenant) Global Administrator must contact Microsoft support directly by phone. Use the numbers listed under the appropriate country/region in Find Microsoft 365 for business support phone numbers by country or region.
    • Explain that:
      • There is only one global administrator.
      • That account is blocked from accessing Partner Center (and/or the tenant) due to Conditional Access or similar restrictions.
      • Access is needed to manage Partner Center and driver signing.
    • Microsoft support will follow the documented tenant-lockout process (for example, identity verification and escalation to internal teams) to help restore access.
    1. If a CSP partner is involved (GDAP/DAP) If the tenant is managed by a Cloud Solution Provider (CSP) partner and there is a Granular Delegated Admin Privileges (GDAP) relationship:
    • Ask the CSP partner to check whether they still have GDAP access with the necessary roles (for example, Global Administrator, Privileged Role Administrator, or roles that can manage Conditional Access or reset access).
    • If the partner has the right GDAP roles, they should:
      • Help restore access (for example, adjust Conditional Access, promote another user to Global Administrator, or help with password/MFA recovery) according to the scenarios in the tenant lockout guidance.
    • If the partner does not have the right GDAP roles or there is no active GDAP relationship, the tenant Global Administrator must contact Microsoft support directly as above.
    1. If access problems are broader than Partner Center If the account cannot sign in at all (not just Partner Center), or there are other account access issues (password, MFA, lost device, etc.):
    • Follow the documented guidance for Troubleshoot sign-in issues and account access problems from the Partner Center support documentation.
    • If locked out and self-service recovery is not possible, escalate to Microsoft support using the business support phone numbers.
    1. Use Partner Center support if the issue is with Partner Center itself (not Conditional Access) If Conditional Access is not the cause and the account can sign in to other Microsoft services but not Partner Center:
    • From another account that can access Partner Center (for example, a CSP partner with GDAP and the Service Support Administrator role), create a support ticket for Partner Center as described in Support from Microsoft.
    • Provide:
      • Tenant ID and Partner Center account details.
      • Error messages/screenshots from the failed Partner Center sign-in or access attempt.
      • Timeline (when driver signing/authentication started failing, when access was restricted).
    • Track the ticket until resolution using the Partner Center support workflow.

    This sequence gives a minimal path:

    1. Confirm whether Conditional Access is blocking Partner Center.
    2. If yes and cannot self-correct, involve the Entra admin or CSP partner with GDAP.
    3. If no admin can sign in or fix it, contact Microsoft 365 business support by phone as a tenant lockout.
    4. If it is a Partner Center–specific issue, open a Partner Center support ticket from an alternate account.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.