A cloud-based identity and access management service for securing user authentication and resource access
For a personal Microsoft account–based Azure tenant where the only admin is locked out due to MFA and no alternative methods are configured, the issue is treated as a tenant lockout and must be handled by Microsoft support/Data Protection.
From the provided scenarios and Q&A resolutions, the supported recovery paths are:
- If there is any other account with Global Administrator rights in the tenant
- Sign in to the Azure portal with that other Global Administrator.
- Go to Microsoft Entra admin center → Identity → Users → All users.
- Select the locked-out user account.
- Open Authentication methods.
- Select Require re-register multifactor authentication.
- Next time the locked-out account signs in, it will be prompted to register MFA again and can configure new methods.
- If there is no other Global Administrator (true tenant lockout)
- This matches the “tenant lockout” / “only global admin locked out due to MFA” situations described in the Q&A excerpts.
- In these cases, recovery is handled by Microsoft’s Data Protection / Tenant Recovery team via a support ticket. They verify tenant ownership and then reset MFA or otherwise restore access.
- Because the only Global Administrator cannot sign in to open a ticket from within the tenant, the case must be escalated to Microsoft support externally (for example, via Microsoft 365/Azure support channels) so that the Data Protection team can:
- Validate identity and tenant ownership using business documentation.
- Reset MFA registration for the locked-out admin account or otherwise restore access.
- If the tenant is associated with a partner (GDAP / CSP scenario)
- If a partner has Granular Delegated Admin Privileges (GDAP) with appropriate roles (for example, Privileged Authentication Administrator or Global Administrator), that partner can:
- Use the same Require re-register multifactor authentication flow in the Microsoft Entra admin center to reset MFA for the affected admin account.
- If the partner does not have the necessary roles, the tenant’s Global Administrator (in this case, the locked-out account) must work with Microsoft support as above.
- If a partner has Granular Delegated Admin Privileges (GDAP) with appropriate roles (for example, Privileged Authentication Administrator or Global Administrator), that partner can:
Given the details provided:
- Only one administrator exists.
- MFA is required and is failing (error 500121, no alternative methods).
This is a tenant lockout. The supported resolution is:
- Engage Microsoft support so the case is routed to the Data Protection/Tenant Recovery team, who will verify ownership and reset MFA/restore access.
References:
- Preventing tenant lockouts
- Mandatory multifactor authentication for Azure and admin portals
- Troubleshoot problems with the My Apps portal
- Troubleshoot Azure Multi-Factor Authentication issues
- Use a screen reader to set up and troubleshoot multifactor authentication
- Reset Personal Azure MFA - Microsoft Q&A
- Global Admin Locked out - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- I need to reset my mfa methods - Microsoft Q&A
- Azure has blocked myphone number for SMS verification due to a “bad reputation” flag - Microsoft Q&A
- Troubleshoot account lockout in AD FS on Windows Server