Azure tenant lockout scenario

2026-04-14T08:54:26.4566667+00:00

Hello, I am locked out of my Azure tenant, which is based on my personal Microsoft account.

Details:

  • I am the only administrator of the tenant
  • Microsoft Authenticator is not working (no push notifications)
  • Verification codes are rejected (error 500121)
  • I have no alternative authentication methods configured

It appears that I have a tenant lockout due to MFA issues.

Please assist with:

  • Resetting MFA for my Azure account
  • Restoring access to the tenant

Thank you.

Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Newest
  1. AI answer

    2026-04-14T08:54:44.76+00:00

    For a personal Microsoft account–based Azure tenant where the only admin is locked out due to MFA and no alternative methods are configured, the issue is treated as a tenant lockout and must be handled by Microsoft support/Data Protection.

    From the provided scenarios and Q&A resolutions, the supported recovery paths are:

    1. If there is any other account with Global Administrator rights in the tenant
      • Sign in to the Azure portal with that other Global Administrator.
      • Go to Microsoft Entra admin centerIdentityUsersAll users.
      • Select the locked-out user account.
      • Open Authentication methods.
      • Select Require re-register multifactor authentication.
      • Next time the locked-out account signs in, it will be prompted to register MFA again and can configure new methods.
      This is the standard, supported way to reset MFA for a user when another Global Administrator exists.
    2. If there is no other Global Administrator (true tenant lockout)
      • This matches the “tenant lockout” / “only global admin locked out due to MFA” situations described in the Q&A excerpts.
      • In these cases, recovery is handled by Microsoft’s Data Protection / Tenant Recovery team via a support ticket. They verify tenant ownership and then reset MFA or otherwise restore access.
      • Because the only Global Administrator cannot sign in to open a ticket from within the tenant, the case must be escalated to Microsoft support externally (for example, via Microsoft 365/Azure support channels) so that the Data Protection team can:
        • Validate identity and tenant ownership using business documentation.
        • Reset MFA registration for the locked-out admin account or otherwise restore access.
    3. If the tenant is associated with a partner (GDAP / CSP scenario)
      • If a partner has Granular Delegated Admin Privileges (GDAP) with appropriate roles (for example, Privileged Authentication Administrator or Global Administrator), that partner can:
        • Use the same Require re-register multifactor authentication flow in the Microsoft Entra admin center to reset MFA for the affected admin account.
      • If the partner does not have the necessary roles, the tenant’s Global Administrator (in this case, the locked-out account) must work with Microsoft support as above.

    Given the details provided:

    • Only one administrator exists.
    • MFA is required and is failing (error 500121, no alternative methods).

    This is a tenant lockout. The supported resolution is:

    • Engage Microsoft support so the case is routed to the Data Protection/Tenant Recovery team, who will verify ownership and reset MFA/restore access.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.