Global admin lockout on Azure tennant

MR-9609 0 Reputation points
2026-04-14T18:57:42.5966667+00:00

With the new azure policy in place, I thought I configured the MFA correctly but I get a 4 digit code response in my browser and no respons on my authenticator app.

Can somebody please help in creating a ticket for the Data protection team ?

Cheers,

Michel Ringoot

Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Oldest
  1. AI answer

    2026-04-14T18:57:59.49+00:00

    Because the tenant’s global admin is effectively locked out by MFA and cannot open a support ticket from the portal, the issue must be escalated to Microsoft Support so the Data Protection/Tenant Recovery team can verify ownership and reset MFA.

    Use these steps:

    1. Check for another global admin
      • If any other global administrator exists in the tenant, that admin should:
        • Sign in to the Azure portal → Microsoft Entra ID → Users → select the affected admin account → Authentication methods → choose Require re-register multifactor authentication so MFA can be set up again.
      • If this is possible, no Data Protection ticket is required.
    2. If there is no other global admin (sole admin scenario)
      • This is a tenant lockout scenario. In this case, only Microsoft Support (Data Protection / Tenant Recovery team) can restore access.
      • Call Microsoft Support using the regional phone number listed under Customer service phone numbers - Microsoft Support.
      • When connected to the IVR/agent, clearly state:
        • The problem is with Microsoft Authenticator / MFA.
        • The product is Office 365 / Microsoft 365 / Azure for business.
        • The account is a company/organization account.
        • The caller is the only global administrator and is locked out by MFA.
        • A service request is needed and must be routed to the Data Protection team (or Tenant Recovery) to reset MFA for the tenant admin.
      • Be prepared to provide tenant-identifying information and business documentation so the Data Protection team can verify ownership.
    3. If phone support is difficult to reach
      • As an alternative, create a temporary new tenant (for example, via a Microsoft 365 trial) and use that tenant’s admin center to open a support ticket.
      • In the ticket, explain that the original tenant’s only global admin is locked out by MFA and explicitly request escalation to the Data Protection team for MFA reset/tenant recovery.

    Once Data Protection verifies ownership, they can reset the MFA registration so the global admin can sign in again and reconfigure MFA correctly.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.