Conditional Access Lockout – Global Admin + User Impact, Tenant Missing from Partner Center

Wayne Klug 0 Reputation points
2026-04-15T00:50:56.1033333+00:00

Hi @Anonymous (tagging for visibility, as you assisted us with a similar incident previously),

We are experiencing a critical Conditional Access–related lockout affecting one of our client tenants.

Current Situation:

  • Our Global Admin account for the tenant is unable to authenticate.
  • A client user (Karen) is also unable to sign in to Microsoft 365 with the same failure pattern.
  • We tested authentication from multiple geographic regions (France, Belize, etc.) to rule out location‑based CA restrictions — all attempts failed identically.
  • The tenant is no longer visible in Microsoft Partner Center, which indicates delegated admin access is also impacted.
  • Pax8 has opened a support ticket with Microsoft (TrackingID: 2604140040008169), and we have provided backend sign‑in details to assist the investigation.

This appears to be a tenant‑level Conditional Access or authentication policy issue that is blocking both privileged and standard user access, as well as partner delegation.

Request:

If possible, we would appreciate your guidance and help in escalating this critical matter.

Thank you in advance — your help last time was instrumental, and we’re hoping to get this tenant back online as quickly as possible.

Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Most helpful
  1. AI answer

    2026-04-15T00:51:22.74+00:00

    Based on the symptoms, this aligns with a tenant-level lockout driven by Conditional Access or related access controls, impacting both administrators and users, and also affecting partner visibility.

    Actionable steps are:

    1. Use any remaining unblocked admin to disable the blocking policy
      • If there is any other administrator account (including a break-glass/emergency account) that can still sign in, use it to:
        1. Go to Microsoft Entra admin center → Conditional Access.
        2. Identify and disable the policy (or policies) that are blocking sign-in.
      • This is the primary remediation path when at least one admin is still able to authenticate.
      • Guidance: see the “What to do if you're locked out” section in Conditional Access troubleshooting.
    2. If no admin can sign in, rely on Microsoft support to adjust Conditional Access
      • When all admins are locked out and no break-glass account works, Microsoft support must intervene to update the Conditional Access policies that prevent access.
      • The correct action is already in progress in your case: Pax8 has opened a support ticket with Microsoft. Continue working through that ticket and avoid opening duplicates while it is active.
      • Official guidance: if no admin can update the policy, submit a support request so Microsoft can review and, after confirming, update the Conditional Access policies that prevent access.
    3. Partner Center “Access restricted due to conditional access policy” / tenant not visible
      • When Conditional Access is misconfigured, Partner Center enforces those policies and cannot override them.
      • Microsoft cannot directly change your organization’s Conditional Access configuration from Partner Center; it must be done either by an unblocked admin or via the Microsoft support path described above.
      • Since the tenant is no longer visible in Partner Center and GDAP access is impacted, resolution depends on restoring tenant access via Microsoft support (step 2). Once access is restored and GDAP/relationship issues are corrected, the tenant should reappear in Partner Center.
    4. If this is effectively a tenant lockout scenario
      The behavior matches the “Conditional Access Policy or Unusual Activity preventing tenant access for all end customers and Partner” scenario:
      • The end-customer Global Administrator of the tenant must work with Microsoft support to restore access.
      • If a partner needs to open or manage the service request on behalf of the customer, the partner must have an active GDAP relationship with the appropriate support role (Service Support Administrator). In your case, because the tenant is missing from Partner Center, this will likely need to be addressed after access is restored.
    5. Preventive measures once access is restored
      After Microsoft support unblocks the tenant and you regain admin access:
      • Ensure at least two cloud-only emergency access (“break-glass”) accounts are permanently assigned Global Administrator and excluded from Conditional Access policies, so that a similar lockout cannot recur.
      • Review Conditional Access design to avoid blanket policies that apply to all admins and all accounts; always exclude break-glass accounts and test policies before broad deployment.
      • For partner scenarios, review GDAP roles and relationship expiration to ensure the partner retains the right roles (for example, Privileged Authentication Administrator, Global Administrator, or Service Support Administrator) to assist with future access issues.

    Given that a Microsoft support ticket is already open with backend sign-in details, the next step is to continue working through that ticket so Microsoft can validate tenant ownership and adjust the blocking Conditional Access configuration.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.