Locked out of Azure AD tenant – Only Global Admin lost MFA and cannot verify identity

Damian Gonzalez 5 Reputation points
2026-04-22T04:15:30.2133333+00:00

I am the only Global Administrator of my Azure Active Directory (Entra ID) tenant. My work account is:

PII

I accidentally erased my Microsoft Authenticator app, and I no longer have access to my only registered MFA method. When attempting to sign in, I am blocked at the MFA verification step.

I have no backup authentication methods (no phone number, no alternate email, no FIDO key, no Temporary Access Pass). Self‑service password reset (SSPR) fails with the message:

“We can’t verify your identity.”

Because MFA is enforced on my admin account, I cannot access:

Azure Portal

Entra admin center

Microsoft 365 admin center

Any Microsoft login flow (all redirect to MFA)

The Azure Support blade (requires sign‑in)

I am completely locked out of the tenant.

I need assistance with a Global Administrator MFA Reset and this personal microsoft account is my recovery email tied to this tenant

Thank you.

Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Newest
  1. AI answer

    2026-04-22T04:15:49.8966667+00:00

    Because the only Global Administrator account is fully locked by MFA and no backup methods are available, this is a tenant lockout scenario that cannot be fixed from within the portals or by self‑service.

    Use the following path to regain access:

    1. Contact Microsoft support / Data Protection team
      • This situation matches the documented tenant lockout and “only global admin” scenarios where Microsoft’s Data Protection team must intervene.
      • Call Microsoft support using the regional business support numbers listed under Customer service phone numbers - Microsoft Support or Support for Business Products. Frontline support will route the case to the Microsoft 365 or Azure Data Protection team for tenant recovery.
      • Clearly state:
        • This is a tenant lockout.
        • There is only one Global Administrator.
        • MFA is enforced and the only method (Microsoft Authenticator) was lost/erased.
        • SSPR fails with “We can’t verify your identity.”
      • Be prepared to provide business and tenant details so the Data Protection team can verify identity and ownership of the tenant.
    2. If the tenant is through a partner (CSP / GDAP)
      • If a Cloud Solution Provider (CSP) or partner manages the subscription and has granular delegated admin privileges (GDAP) with password reset–capable roles, that partner can work directly with the customer to restore access (reset password / MFA) without Microsoft escalation.
      • If the partner has GDAP but no password reset roles, the end‑customer Global Administrator must contact Microsoft support as above; the partner should help the customer use the self‑service password reset tool where possible, but in this case SSPR is already failing, so escalation to Microsoft is required.
    3. If absolutely no way to open a ticket from the locked tenant
      • If sign‑in to the locked tenant is impossible and there is no other admin, use an external route to reach support:
        • Call the regional Microsoft 365 for business or Azure support phone number and request a Data Protection / Tenant Recovery escalation for a locked global admin account.
        • Alternatively, as described in the guidance, a temporary new Microsoft 365 trial tenant can be created solely to open a support ticket. In that ticket, clearly state that the issue concerns a different existing tenant where the only Global Administrator is locked out by MFA.
    4. What Microsoft will do
      • The Data Protection team has internal tools and processes to:
        • Verify identity and administrative rights for the locked tenant.
        • Reset or clear MFA registration for the Global Administrator account, or otherwise restore access.
      • After access is restored, immediately:
        • Add at least one additional Global Administrator.
        • Configure multiple MFA methods (Authenticator, phone, FIDO2/passkey, etc.).
        • Consider setting up a break‑glass account with appropriate protections.

    Self‑service options such as “I don’t have any of these” during sign‑in, SSPR, or changing security info cannot complete in this scenario because all security methods are lost and there is no second admin. Direct engagement with Microsoft support / Data Protection is required.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.