The Admin user of Azure is not able to login due to Authenticator access was deleted on phone. Other type of verification is not enabled. Is there a solution. The QR codes is also not able to retrieve.

Ridco User 4 0 Reputation points
2026-04-22T12:05:09.8233333+00:00

The Admin user of Azure is not able to login due to Authenticator access was deleted on phone. Other type of verification is not enabled. Is there a solution. The QR codes is also not able to retrieve.

Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Oldest
  1. AI answer

    2026-04-22T12:05:31.9366667+00:00

    Yes, there are solutions, depending on whether there is another administrator in the tenant.

    1. If there is another Global Admin / Entra ID admin That admin can reset the locked-out admin’s MFA so it can be set up again:
      1. Sign in to the Azure portal as an admin.
      2. Open Microsoft Entra ID.
      3. Go to Users and select the affected admin account.
      4. Open Authentication methods.
      5. Select Require re-register multifactor authentication.
      Next time the locked-out admin signs in, the account will be prompted to register MFA again (scan a new QR code or configure another method). This is the same pattern used in:
      • “Require re-register multifactor authentication” described for users whose MFA methods must be reset.
      • The Q&A resolutions where another admin resets MFA so the user can re-enroll Authenticator.
    2. If the locked-out admin is the only Global Admin In this case, self-service recovery is not possible because there is no other admin to reset MFA and no alternative verification method is configured. The documented path is to involve Microsoft Support / Data Protection team so they can verify tenant ownership and reset MFA for the admin:
      • Contact Microsoft support via the regional customer service phone number and clearly state:
        • The issue is with Authenticator and Office 365/Azure for business.
        • It is a company/education account.
        • The caller is the only administrator and is locked out due to MFA.
      • The frontline agent escalates to the Data Protection / Tenant Recovery team, who will verify identity and then reset MFA registration for the admin account.
      If direct support access is blocked, one documented workaround is:
      • Create a new trial Microsoft 365 tenant.
      • From that new tenant’s Microsoft 365 Admin Center, open a support ticket explaining that access is needed to a different, existing tenant where the admin is locked out by MFA.
      • Provide the locked tenant’s domain, admin UPN, and error details so support can route the case to the Data Protection team.
    3. General notes
      • Old QR codes cannot be reused; MFA must be reset and re-registered.
      • After recovery, configure multiple MFA methods (Authenticator plus phone/SMS, etc.) and consider having at least one additional Global Admin or break-glass account to avoid future lockout.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.