A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
The tenant is effectively locked out of MFA/security management because the only available MFA method (an authenticator app on a device no one controls) is inaccessible. In this situation, self‑service recovery is not possible and the tenant must be recovered by Microsoft support/Data Protection.
Use these steps depending on whether there is any other global admin available:
- Check for any other global admin
- If there is another global administrator who can still pass MFA, that admin can reset MFA for affected users by requiring re‑registration of MFA methods, as described in the guidance referenced in the Q&A thread about resetting MFA methods. This restores the ability to configure new MFA methods for those users.
- If there is only one global admin (or all admins are blocked by MFA)
- This is a tenant lockout scenario. The only supported path is to work with Microsoft’s Data Protection team via a support ticket.
- Contact Microsoft support using the global support phone numbers listed in the documentation. Clearly state that:
- The organization is locked out of MFA/security settings.
- The only admin (or all admins) cannot complete MFA because the authenticator app is no longer accessible.
- The frontline agent will route the case to the Data Protection team, which has tools and processes to verify identity and restore access to the administrator account and tenant.
- If unable to open a ticket from the locked tenant
- If the tenant admin portal cannot be accessed at all, create a separate temporary Microsoft 365 trial tenant solely to open a support request, as described in the Q&A guidance:
- Sign up for a trial tenant.
- Go to the Microsoft 365 admin center → Support → Help & support.
- Open a service request explaining that the request is about a different, existing tenant (
365office.site) where the admin is locked out by MFA. - Provide the locked tenant’s domain, admin UPN, and error details (including the
[4o6fs]sign‑in failure and the inaccessible MFA prompt).
- This trial tenant will not give access to data in the original tenant; it is only a channel to reach support. Remember to cancel the trial once the original tenant is recovered.
- If the tenant admin portal cannot be accessed at all, create a separate temporary Microsoft 365 trial tenant solely to open a support request, as described in the Q&A guidance:
- What Microsoft will do
- The Data Protection team will verify ownership and admin rights for the
365office.sitetenant (using business documentation and other checks) and then:- Reset MFA for the locked admin(s) or
- Restore access so that new MFA methods can be configured.
- The Data Protection team will verify ownership and admin rights for the
Until Microsoft support/Data Protection resets MFA or restores access, security/MFA management for the tenant cannot be recovered from the portal alone.
References:
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- I need to reset my mfa methods - Microsoft Q&A
- Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A