A cloud-based identity and access management service for securing user authentication and resource access
Because the tenant’s global admin is effectively locked out by MFA and cannot open a support ticket from the portal, the issue must be escalated to Microsoft Support so the Data Protection/Tenant Recovery team can verify ownership and reset MFA.
Use these steps:
- Check for another global admin
- If any other global administrator exists in the tenant, that admin should:
- Sign in to the Azure portal → Microsoft Entra ID → Users → select the affected admin account → Authentication methods → choose Require re-register multifactor authentication so MFA can be set up again.
- If this is possible, no Data Protection ticket is required.
- If any other global administrator exists in the tenant, that admin should:
- If there is no other global admin (sole admin scenario)
- This is a tenant lockout scenario. In this case, only Microsoft Support (Data Protection / Tenant Recovery team) can restore access.
- Call Microsoft Support using the regional phone number listed under Customer service phone numbers - Microsoft Support.
- When connected to the IVR/agent, clearly state:
- The problem is with Microsoft Authenticator / MFA.
- The product is Office 365 / Microsoft 365 / Azure for business.
- The account is a company/organization account.
- The caller is the only global administrator and is locked out by MFA.
- A service request is needed and must be routed to the Data Protection team (or Tenant Recovery) to reset MFA for the tenant admin.
- Be prepared to provide tenant-identifying information and business documentation so the Data Protection team can verify ownership.
- If phone support is difficult to reach
- As an alternative, create a temporary new tenant (for example, via a Microsoft 365 trial) and use that tenant’s admin center to open a support ticket.
- In the ticket, explain that the original tenant’s only global admin is locked out by MFA and explicitly request escalation to the Data Protection team for MFA reset/tenant recovery.
Once Data Protection verifies ownership, they can reset the MFA registration so the global admin can sign in again and reconfigure MFA correctly.
References:
- Troubleshoot sign-in problems with Conditional Access
- Preventing tenant lockouts
- Common problems with two-step verification for a work or school account
- I need to reset my mfa methods - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Global Admin Locked out - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- You don't receive a text or voice call that contains the verification code for Microsoft Entra multifactor authentication
- "Activation failed" error when you try to set up Azure Multi-Factor Authentication
- Mandatory multifactor authentication for Azure and admin portals
- Require multifactor authentication for admins accessing Microsoft admin portals