An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
For a locked-out global admin with no other admins and no support plan, the path is through Microsoft’s Data Protection / Tenant Recovery teams via standard support channels. The key is: sign-in issues and global-admin lockouts are handled even without a paid support plan, but they must be initiated by someone who is (or is supposed to be) part of the affected tenant.
Below is the procedure mapped to the questions.
- Free sign-in support / MFA reset path
For a tenant where the admin cannot complete MFA and there are no other global admins:
- The affected admin (or another user already in that tenant) must contact Microsoft’s Data Protection team by phone as a sign-in issue.
- For Microsoft 365 / Entra tenants, use the regional phone numbers listed under Microsoft 365 business support: see “Find Microsoft 365 for business support phone numbers by country or region”.
- For Azure-only scenarios where the caller is the only global admin, the guidance is the same pattern as in Partner Center: contact the Data Protection team via the global support phone numbers.
- Clearly state during the call:
- They are the global admin (or intended global admin) for the tenant.
- They are locked out due to MFA / verification and cannot sign in to open a ticket.
- There are no other global admins available.
- The Data Protection team then uses internal verification processes to:
- Reset credentials or
- Reset MFA / security info or
- Otherwise restore an admin account so that access to the tenant can be regained.
This pattern is documented in multiple places:
- For “only global admin” scenarios, the Data Protection team is explicitly called out as the escalation path. See the “Solve account access problems” table where “You’re the only global admin on the account” is handled by contacting the Data Protection team via phone.
- For “regain access to a tenant owned by my organization”, the documented step is: open a support ticket and the Data Protection Team can reset credentials of an administrator account or help claim ownership of the tenant.
- For global admins locked out due to MFA with no other admins, moderators on Microsoft Q&A direct users to call the Data Protection team via the global support phone numbers and have a ticket raised for tenant recovery / MFA reset.
There is no separate public “MFA reset” web form; the supported route is a sign-in / account-access support case via phone, routed to the Data Protection team.
- Admin takeover as fallback
Admin takeover is documented for unmanaged directories (a.k.a. unmanaged tenants) created via self-service sign-up. The documented guidance is:
- Review domains in the registrar that are not verified to the home tenant.
- If a paid domain is associated with an unmanaged directory, a global admin can perform an admin takeover of that unmanaged directory.
For a managed production tenant where the organization already has an established subscription and admin, the documented recovery path is via the Data Protection team, not admin takeover. Admin takeover is appropriate when the tenant is unmanaged and effectively “orphaned,” not when a managed tenant has a locked-out admin.
So for this scenario (existing production subscription, known tenant, locked-out admin), the correct fallback is still:
- Open a support case with Microsoft (phone → Data Protection team) to reset admin credentials/MFA.
- Reaching a human agent (script)
Based on documented patterns and Q&A moderator guidance, the following script aligns with how calls are expected to be handled:
Caller must be someone in the affected organization (ideally the locked-out admin):
- Call the regional Microsoft support number for business products (for example, from the “global support phone numbers” or “Microsoft 365 for business support phone numbers by country or region”).
- When prompted by the automated system, use phrases that classify the issue as a sign-in problem for a business tenant, for example:
- “Sign-in problem for Microsoft 365 / Azure for business.”
- “Global administrator locked out.”
- “Cannot complete multifactor authentication.”
- When asked about role and tenant:
- “This is a company account.”
- “I am the global administrator.”
- “There are no other global administrators.”
- When asked what is needed:
- “I need to open a service request with the Microsoft Data Protection team to regain access to our tenant. I cannot sign in because MFA / verification fails.”
This mirrors the Q&A moderator guidance where callers are instructed to explicitly state they are the only admin, locked out due to Authenticator/MFA, and need a service request raised for Data Protection.
- Partner escalation (CSP / GDAP)
If a CSP partner is involved, the documented pattern is:
- The partner must have an active GDAP relationship with the customer and appropriate roles.
- For creating a service request on behalf of the customer, the partner needs the Service Support Administrator role via GDAP.
- With that, the partner can “report problems on behalf of a customer” and open a support request.
For a “tenant admin needs MFA reset / sign-in recovery” scenario, the partner should:
- Ensure there is an active GDAP relationship with the customer tenant and that the partner account has the Service Support Administrator role.
- Use Partner Center’s “Report problems on behalf of a customer” flow and select a support category under sign-in / account access / admin access problems (the exact UI labels can vary, but the scenario is “tenant lockout / admin cannot sign in”).
- In the case description, clearly state:
- Customer’s tenant ID and primary domain.
- That the customer’s global admin is locked out due to MFA / verification and there are no other global admins.
- That the request is to have the Data Protection team reset the admin’s credentials/MFA so they can regain access.
If the partner does not have the right GDAP roles or no GDAP relationship exists, the documented guidance is that Microsoft must work directly with a global admin on the customer tenant. In that case, the customer’s own global admin (or intended admin) must call Microsoft support as described above.
Summary to relay to the client’s admin
- This is a standard “only global admin locked out” scenario.
- The supported path is to call Microsoft’s business support number, classify it as a sign-in issue, and have a case routed to the Data Protection team.
- No paid support plan is required for sign-in / tenant-access issues.
- Admin takeover is for unmanaged tenants and is not the primary recovery method for a managed production tenant; instead, use Data Protection.
- If a CSP partner with GDAP exists, they can open a “report problem on behalf of a customer” ticket under sign-in / tenant access and have it escalated the same way.
References: