Global Admin Locked Out – Tenant Recovery Required. Tenant Locked Out – Data Protection Escalation. M365 Tenant Locked Out – No Global Admin

Rob Harrison 0 Reputation points
2026-04-24T01:13:01.3533333+00:00

ADMIN TENANT LOCKOUT – DATA PROTECTION ESCALATION REQUIRED

This support request is being submitted from my personal Microsoft account solely to access support. The affected Microsoft 365 business tenant is a different tenant and is fully locked out.

We have a Microsoft 365 business tenant that is completely locked out. The only Global Administrator account is inaccessible, billing failed due to a credit card change, and all multi‑factor authentication and recovery methods route to the same email mailbox, which cannot be accessed.

There are no remaining administrators in the tenant, making self‑service recovery impossible due to a closed authentication loop.

I am a company director and authorised representative of Baird Street Capital. The tenant was originally set up by the other director, who did not add me as an administrator and configured the Global Administrator account with no alternate recovery methods.

I can provide ASIC proof of directorship, proof of domain and DNS control, and billing and subscription history for the tenant.

This is a tenant‑level recovery request, not a password reset. I am requesting ownership verification and restoration of Global Administrator access.

Please escalate this case to the Microsoft Data Protection Team.

Microsoft Security | Microsoft Entra | Microsoft Entra ID

Locked Question. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

1 answer

Sort by: Newest
  1. AI answer

    2026-04-24T01:13:19.7033333+00:00

    Tenant-level recovery and restoration of Global Administrator access for a locked-out Microsoft 365 business tenant must be handled directly by Microsoft’s Data Protection team. Forum posts or requests from a personal account cannot trigger that process.

    To proceed, the authorized representative of the organization must open a support case with Microsoft and request escalation to the Data Protection / Tenant Recovery team, then complete their identity and ownership verification.

    Use one of these supported paths:

    1. Contact Microsoft by phone (recommended for locked-out tenants)
      • Call the global customer service number for the appropriate region: see Customer service phone numbers - Microsoft Support.
      • When prompted by the IVR, clearly indicate:
        • The issue is with Microsoft 365 for business.
        • It is a company/organization account.
        • The caller is an administrator and there is no other Global Administrator.
        • The tenant is locked out and Data Protection / Tenant Recovery assistance is required.
      • Ask explicitly to be routed to the Microsoft 365 Data Protection team for tenant ownership verification and admin recovery.
    2. If portal access is available from any account in the tenant
      • If any user account in the affected tenant can still sign in, that user can:
        • Go to the Microsoft 365 admin help and support entry point and open a support ticket.
        • In the ticket, state that the only Global Administrator is inaccessible, there is no other GA, and request escalation to the Data Protection team for tenant recovery.
    3. If no one can sign in to the affected tenant at all
      • Use a different tenant or a temporary trial tenant only as a channel to reach support:
        • Create a separate Microsoft 365 trial tenant.
        • From that tenant’s admin center, open a support ticket.
        • Clearly state that the ticket concerns a different, existing Microsoft 365 tenant (provide its primary domain and admin UPN), that the only GA is inaccessible, and that tenant-level recovery and GA restoration are required.
      • Be prepared to provide to Microsoft support/Data Protection:
        • Official business documentation (for example, ASIC proof of directorship).
        • Evidence of domain ownership/DNS control for the tenant’s primary domain.
        • Billing and subscription history associated with the tenant.
    4. If the tenant is inaccessible due to inactivity
      • If sign-in returns an error such as AADSTS5000225: This tenant has been blocked due to inactivity, an administrator must:
        • Contact Microsoft using the global support phone numbers.
        • Request tenant reactivation and follow the same Data Protection verification process.
    5. If there is truly no Global Administrator on record
      • When there is no usable GA and no partner with GDAP access, Microsoft’s documented path is:
        • The organization (or a user who is part of the tenant, if any) must contact Microsoft 365 support by phone.
        • Ask to be transferred to the Microsoft 365 Data Protection team to:
          • Verify organizational ownership.
          • Reset credentials for an administrator account or assign Global Administrator to the verified representative.

    In all cases, Microsoft for Nonprofits, community moderators, or partners cannot bypass identity verification or directly grant access. All tenant ownership and access decisions are made only through Microsoft 365 support and the Data Protection team after verification of:

    • Organization identity.
    • Domain ownership.
    • Relationship of the requester to the organization (for example, director/authorized representative).

    Once verification is complete, the Data Protection team can:

    • Reset credentials for an existing admin account, or
    • Assign or restore Global Administrator access to an appropriate account, allowing full tenant recovery.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?