A cloud-based identity and access management service for securing user authentication and resource access
For a sole Microsoft Entra/Microsoft 365 admin who lost access to the Microsoft Authenticator app and has no alternative MFA method, recovery must go through Microsoft support and the Data Protection team.
Actionable options:
- Confirm there is no other admin or MFA method
- If any other global admin exists in the tenant, that admin can sign in and reset MFA for the locked account via Microsoft Entra admin center (Users → select the user → Authentication methods → require re-register multifactor authentication).
- If there is no other admin and no working alternative sign-in method (SMS, email, security key), proceed to the next steps.
- Contact Microsoft Support by phone and request Data Protection team
This is the primary and supported path when the only global admin is locked out:- Call the appropriate Customer service phone number for the region: see Customer service phone numbers - Microsoft Support (from context).
- When the IVR/automated system asks questions, follow a flow similar to:
- Problem type: say “Authenticator”.
- Product: “Office 365 for business”.
- Account type: “For companies”.
- Are you an administrator?: “Yes”.
- Are there any other administrators?: “No”.
- When asked about a service request: answer “Yes” and ask to be routed to the Data Protection team to reset the admin MFA.
- Clearly state:
- You are the only global admin on the tenant.
- You are locked out due to lost/reset phone and no Authenticator backup.
- You need an MFA reset / re‑registration for the tenant admin account.
- Be prepared to provide business and identity verification details (tenant domain, admin UPN, company details, contact info, etc.). The Data Protection engineers will validate identity and then reset MFA so that a new method (e.g., new Authenticator app, plus an additional method) can be configured.
- If phone support is hard to reach: create a temporary trial tenant to open a ticket
If it is not possible to get to a live agent directly:- Sign up for a new Microsoft 365 trial tenant (separate from the locked tenant).
- In the new tenant, go to the Microsoft 365 admin center → Support → Help & support.
- Open a support ticket explaining that:
- The issue is with a different, existing tenant where you are the only global admin.
- You are locked out due to MFA on Microsoft Authenticator and have no alternative method.
- You need the Data Protection team to verify identity and reset MFA on the original tenant.
- This trial tenant is only a channel to reach support; it does not give access to data in the locked tenant. Remember to cancel the trial after the original tenant issue is resolved.
- What to expect
- The Data Protection process can take several days, as shown in similar resolved cases.
- After verification, a Data Protection engineer will reset/re‑register MFA for the admin account and can help add an additional authentication method to avoid future lockouts.
There is no self-service way to bypass MFA when the only admin is locked out and no backup methods exist; escalation to Microsoft’s Data Protection team via support is required.
References:
- Common problems with two-step verification for a work or school account
- How Do I Regain Access to My Account After Losing Access to Microsoft Authenticator? (Urgent Request). - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A