A cloud-based identity and access management service for securing user authentication and resource access
For a single Global Administrator who is locked out by MFA and has no other admin in the tenant, the only supported recovery path is through Microsoft support and the Data Protection/Tenant Recovery process. CLI access with az login does not allow bypassing or resetting MFA for the Global Admin account.
Use these steps, depending on the situation:
- If there is any other admin with sufficient rights (Global Administrator, Privileged Role Administrator, Authentication Administrator, or another role with permission to reset authentication methods):
- That admin must sign in to the Azure portal → Microsoft Entra ID → Users → select the locked-out admin account → Authentication methods → select Require re-register multifactor authentication. This forces MFA re-registration on next sign-in.
- This is the standard resolution when another admin exists and is not blocked.
- If there is no other admin and this is a tenant lockout scenario (only Global Admin is locked out):
- This is treated as a tenant lockout / Data Protection case.
- A support request must be opened so Microsoft can verify tenant ownership and reset MFA for the admin account.
- Because the locked-out admin cannot open a ticket from the affected tenant, use one of these options from the provided guidance:
- Call Microsoft’s global customer service phone numbers and explicitly request a Data Protection / Tenant Recovery case for “Global Admin locked out due to MFA, no other admin.” The support workflow then routes to the Data Protection team, who will contact the admin, verify identity, and reset MFA registration.
- If phone support is difficult to reach, create a temporary trial Microsoft 365/Azure tenant, sign in as admin of that new tenant, and from that admin center open a support ticket requesting Data Protection assistance for the original tenant. The Data Protection team will then work the lockout on the original tenant.
- If the lockout is caused by Conditional Access (for example, a misconfigured policy blocking the only admin):
- If any other admin is still able to sign in, that admin must disable or adjust the Conditional Access policy as described in the Conditional Access troubleshooting guidance.
- If no admin can sign in at all because of Conditional Access, a support request must be submitted so Microsoft support can review and update the Conditional Access policies that prevent access.
- If the issue is specifically loss of phone or phone number used for MFA:
- Another cloud services admin (if available) can reset MFA settings using the legacy MFA management page so that the admin re-enters contact methods.
- If there is no other admin, this again falls under the Data Protection / tenant lockout process and must be handled by Microsoft support as above.
In all single-admin lockout cases, self-service or CLI-based MFA reset is not available; recovery requires Microsoft support to verify ownership and reset MFA or security info for the Global Admin account.
References:
- Can't use Azure Multi-Factor Authentication to sign in to cloud services after you lose your phone or the phone number changes
- Troubleshoot sign-in problems with Conditional Access
- Preventing tenant lockouts
- Common problems with two-step verification for a work or school account
- Global Admin Locked out - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- How Do I Regain Access to My Account After Losing Access to Microsoft Authenticator? (Urgent Request). - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- I need to reset my mfa methods - Microsoft Q&A