A cloud-based identity and access management service for securing user authentication and resource access
For a locked tenant or Global Administrator account where no other global admin can help, the Microsoft Data Protection Team must be engaged to restore access.
Follow these steps:
- Confirm there is no other Global Administrator
If another global admin exists in the tenant, that admin should sign in to the Azure portal → Microsoft Entra ID → Users → select the locked admin account → Authentication methods → Require re-register multifactor authentication. This forces MFA re-registration and typically resolves access issues. - If you are the only Global Administrator (tenant lockout)
In a true tenant lockout scenario (only global admin is locked and cannot sign in to any admin portal or open a ticket):- Open a support case with Microsoft and request escalation to the Data Protection Team. They are the only team that can:
- Reset credentials of an administrator account.
- Help regain access to a tenant owned by the organization.
- Use the global customer service phone numbers listed under Global Customer Service phone numbers and clearly state:
- The issue is a tenant lockout.
- The caller is the only Global Administrator.
- Escalation is needed to the Microsoft Data Protection Team / Tenant Recovery.
- Open a support case with Microsoft and request escalation to the Data Protection Team. They are the only team that can:
- If completely unable to open a ticket from the locked tenant
As shown in similar cases, if sign-in to the original tenant is impossible, one of these approaches is used:- Call the regional support number directly and ask the agent to create a Data Protection / Tenant Recovery ticket on behalf of the locked tenant. Provide:
- Tenant domain name.
- Global admin UPN/email for the locked account.
- Description of the lockout (MFA lost, account locked, etc.).
- If frontline support cannot route correctly, some customers create a temporary trial tenant, sign in as admin there, and from that tenant’s Microsoft 365 admin center submit a support request explicitly asking to speak with the Data Protection Team for the original locked tenant. In the ticket, include:
- The original tenant’s domain.
- The locked global admin account.
- Confirmation that this is a tenant lockout and there is no other global admin.
- Call the regional support number directly and ask the agent to create a Data Protection / Tenant Recovery ticket on behalf of the locked tenant. Provide:
- What the Data Protection Team does
After verification of ownership, the Data Protection Team can:- Reset the global admin credentials or MFA methods.
- Help reclaim or confirm ownership of the tenant if needed.
Until the Data Protection Team completes verification and resets access, no one (including forum moderators or standard support agents) can bypass security controls or directly unlock the tenant/global admin account.
References:
- Discover your Microsoft cloud footprint FAQ
- Troubleshoot sign-in issues and account access problems
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- Global Admin Locked out - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A