Can't access my alternate account as I lost access to Authenticator app

Pedro Lacerda 0 Reputation points Microsoft Employee
2026-04-23T19:02:06.22+00:00

My phone, where I had Authenticator configured, was stolen. Now, I can't access my alternate account (******@pedrolacerda.me), where I'm the only admin.

I've tried all recovery methods online and phone support, but I could never speak to a human, nor reset MFA, only the password, which I do have still.

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Oldest
  1. AI answer

    2026-04-23T19:02:21.1333333+00:00

    Because the phone with Microsoft Authenticator was stolen and there is no other admin on the tenant, this is a tenant lockout scenario that cannot be fixed by self-service tools.

    Use these steps to regain access:

    1. Since password sign-in still works but MFA cannot be completed, normal online recovery flows will not help; MFA registration must be reset by Microsoft.
    2. As the only administrator, contact Microsoft’s Data Protection team via the global customer service phone numbers and request an admin/MFA reset for the tenant:
      • Call the number for the region from Customer service phone numbers - Microsoft Support.
      • When interacting with the automated system, clearly indicate:
        • The issue is with Authenticator.
        • The product is Office 365 for business / Microsoft 365 for business.
        • It is a company account.
        • Confirm being an administrator and that there are no other administrators.
        • Ask to create a service request and be routed to the Data Protection team for tenant recovery and MFA reset.
    3. If phone support cannot be reached or does not route correctly, create a temporary trial tenant and open a support ticket from there:
      • Sign up for a Microsoft 365 trial tenant (any business/enterprise plan).
      • In the new tenant, go to the Microsoft 365 admin center → SupportHelp & support.
      • Open a ticket explicitly stating:
        • Being locked out of a different, existing Microsoft 365 tenant.
        • The admin username and domain of the locked tenant.
        • That this is a sole global admin MFA lockout.
        • Request escalation to the Data Protection / Tenant Recovery team to reset MFA for the locked tenant.
      • This trial tenant is only a channel to reach support; it will not give access to data in the locked tenant. Remember to cancel the trial after the issue is resolved.

    Once Microsoft Data Protection verifies identity and ownership, they can reset MFA registration for the locked admin account so that Authenticator (or another MFA method) can be configured again.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

    1 person found this answer helpful.

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.