A cloud-based identity and access management service for securing user authentication and resource access
Yes, there are solutions, depending on whether there is another administrator in the tenant.
- If there is another Global Admin / Entra ID admin
That admin can reset the locked-out admin’s MFA so it can be set up again:
- Sign in to the Azure portal as an admin.
- Open Microsoft Entra ID.
- Go to Users and select the affected admin account.
- Open Authentication methods.
- Select Require re-register multifactor authentication.
- “Require re-register multifactor authentication” described for users whose MFA methods must be reset.
- The Q&A resolutions where another admin resets MFA so the user can re-enroll Authenticator.
- If the locked-out admin is the only Global Admin
In this case, self-service recovery is not possible because there is no other admin to reset MFA and no alternative verification method is configured. The documented path is to involve Microsoft Support / Data Protection team so they can verify tenant ownership and reset MFA for the admin:
- Contact Microsoft support via the regional customer service phone number and clearly state:
- The issue is with Authenticator and Office 365/Azure for business.
- It is a company/education account.
- The caller is the only administrator and is locked out due to MFA.
- The frontline agent escalates to the Data Protection / Tenant Recovery team, who will verify identity and then reset MFA registration for the admin account.
- Create a new trial Microsoft 365 tenant.
- From that new tenant’s Microsoft 365 Admin Center, open a support ticket explaining that access is needed to a different, existing tenant where the admin is locked out by MFA.
- Provide the locked tenant’s domain, admin UPN, and error details so support can route the case to the Data Protection team.
- Contact Microsoft support via the regional customer service phone number and clearly state:
- General notes
- Old QR codes cannot be reused; MFA must be reset and re-registered.
- After recovery, configure multiple MFA methods (Authenticator plus phone/SMS, etc.) and consider having at least one additional Global Admin or break-glass account to avoid future lockout.
References:
- Can't use Azure Multi-Factor Authentication to sign in to cloud services after you lose your phone or the phone number changes
- Can't set up MFA because five devices are already registered to use an authenticator app
- You don't receive a text or voice call that contains the verification code for Microsoft Entra multifactor authentication
- Use a screen reader to set up and troubleshoot multifactor authentication
- Global Admin Locked out - Microsoft Q&A
- How Do I Regain Access to My Account After Losing Access to Microsoft Authenticator? (Urgent Request). - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Reset Personal Azure MFA - Microsoft Q&A
- I need to reset my mfa methods - Microsoft Q&A
- "Account verification system is having trouble" error message when you try to sign in by using a work or school account
- "We did not receive the expected response" error message when you try to sign in by using Azure Multi-Factor Authentication