How to reset or revoke MFA as the one and only Global Admin

Ibiso Dokubo 0 Reputation points
2026-04-17T01:29:32.14+00:00

I need help finding a practical way to contact Microsoft support for an MFA lockout issue.

I support small businesses and sole traders with Microsoft 365, and for some tenants I am the only Global Admin. My Samsung phone suddenly stopped working, so I lost access to the Microsoft Authenticator app linked to several business accounts. This has affected access to up to three accounts that I manage, pay for, and need to maintain urgently.

I have tried to raise support, but the available links direct me to admin portals I cannot access because of the MFA issue itself. I also tried calling, but the automated phone agents misunderstood parts of what I was saying and ended the calls.

I explained that I was willing to complete any practical verification process to prove I am the Global Admin, such as verification by email or phone, billing checks, audit logs, recent account activity, IP address confirmation, or any other reasonable method, but there seemed to be no flexibility beyond the standard process.

How can someone in this situation reach a real Microsoft support person and recover access when they are locked out by MFA and are the only Global Admin?

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-04-17T01:29:49.56+00:00

    When the only Global Administrator is locked out by MFA and cannot access any admin portal, recovery must go through Microsoft support’s Data Protection process by phone. Online support flows that require portal access will not work in this scenario.

    Use this approach for each affected tenant:

    1. Call Microsoft’s global support number for Microsoft 365 for business
    2. Navigate the IVR specifically to reach Data Protection
      • When prompted by the automated system, answer along these lines (as documented in similar resolved cases):
        • Problem type: say “Authenticator” or “multi-factor authentication”.
        • Product: “Office 365 for business” or “Microsoft 365 for business”.
        • Account type: “For companies”.
        • Are you an administrator?: “Yes”.
        • Do you have another administrator?: “No. I am the only admin in my tenant.”
        • Do you need a service request?: “Yes. I need to create a ticket. Please send me to the Data Protection team.”
      • In some regions you may first need to press “1” for business email user and “1” again for technical help before the voice prompts.
    3. Clearly state the scenario to the frontline agent
      • Explain that:
        • You are the only Global Administrator for the tenant.
        • You are locked out due to MFA (lost phone / Authenticator not accessible).
        • You cannot access the Microsoft 365 admin center or Entra admin center to reset MFA.
      • Ask explicitly for a ticket to be opened with the “Data Protection team” to reset the authentication methods for the Global Admin account.
    4. Complete Data Protection verification
      • The Data Protection team is the only group allowed to reset MFA for a sole Global Admin in a tenant lockout scenario. They will:
        • Contact via phone or email and run through their identity verification process.
        • After verification, reset MFA or authentication methods on the admin account so sign-in can be completed and MFA re-registered.
      • The exact verification steps are internal to Microsoft and cannot be bypassed; there is no alternative self-service route when there is no other Global Admin.
    5. If calls keep failing or being misrouted
      • Call again and follow the IVR wording above as closely as possible; the phrasing is important to reach the correct queue.
      • If still unable to reach a live agent, one documented workaround is:
        • Create a new, temporary Microsoft 365 tenant using a trial subscription.
        • Use that new tenant’s admin center to open a support ticket requesting that Microsoft support/Data Protection assist with the original locked tenant.
    6. For tenants where there is another Global Admin
      • If any affected tenant has another Global Admin, that admin can:
        • Sign in to Microsoft Entra admin center (https://entra.microsoft.com).
        • Go to Users → All users → select the locked-out account → Authentication methods.
        • Choose “Require re-register multifactor authentication”.
      • This forces MFA re-registration at next sign-in without needing Microsoft support.
    7. Preventing future lockouts
      • For each tenant once access is restored:
        • Add at least one additional Global Administrator.
        • Configure multiple MFA methods (Authenticator on a second device, phone, etc.).
        • Ensure another trusted person or partner has sufficient admin rights to reset MFA.

    In summary, when the only Global Admin is locked out by MFA, recovery must go through Microsoft’s phone support and the Data Protection team using the global support numbers; there is no portal-based or self-service alternative in this scenario.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.