A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Since the admin account is protected by MFA and the Microsoft Authenticator app was not set up correctly on the new phone, and no alternative MFA method is being offered at sign-in, this requires direct support intervention.
For a work or school (business) account where the locked-out user is the only admin/tenant administrator:
- Contact Microsoft Data Protection / Commercial Support by phone
Use the regional number from Customer service phone numbers - Microsoft Support (as described in the referenced Q&A). When the automated system asks questions, respond along these lines to reach the correct team:- Problem type: say “Authenticator”.
- Product: “Office 365 for business”.
- Account type: “For companies”.
- Are there other admins?: “No, I am the only administrator.”
- Request: “Yes, I need to create a ticket and speak with the Data Protection team for an admin MFA reset.”
- If phone support cannot be reached, create a temporary trial tenant to open a ticket
- Sign up for a Microsoft 365 trial tenant (as described in the Q&A) and complete setup.
- Go to the new tenant’s Microsoft 365 Admin Center (
https://admin.microsoft.com/). - Open Support → Help & support and create a support request.
- In the ticket, clearly state that this new tenant is only for contact, and provide:
- The admin email and domain of the original locked tenant.
- That this is a Tenant Admin MFA reset request and that there is no other admin.
- Error behavior at sign-in (only Authenticator prompt, no SMS/email options).
For a personal Microsoft/Hotmail/Outlook.com account (not work/school):
- Use the Microsoft account recovery form
- Go to the Account recovery form from a familiar device and location (home/office) as recommended in Help with the Microsoft account recovery form.
- Provide a working email address that can receive responses.
- Fill in as much accurate information as possible; Microsoft will review and respond, typically within 24 hours.
- If two-step verification is enabled and none of the configured methods (Authenticator, phone, email) are accessible, support agents cannot bypass MFA, send reset links, or change security details for consumer accounts. In that case, the recovery form is the only supported path.
- If verification codes are not being received on phone or email, review the guidance in Common problems with two-step verification for a work or school account (many points also apply generally): avoid repeated requests, check junk mail for messages from
@accountprotection.microsoft.com, ensure the phone can receive SMS from unknown numbers, and avoid VOIP numbers.
Because the sign-in page is not offering SMS or secondary email as options, and the Authenticator app is unusable, self-service recovery is not sufficient for an admin work account; contacting Microsoft via phone or via a trial-tenant support ticket and asking specifically for a Tenant Admin MFA reset/Data Protection team is required.
References:
- Help with the Microsoft account recovery form
- Common problems with two-step verification for a work or school account
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Can't sign in to my email - Microsoft Q&A
- I need to speak with a real person and it seems impossible. - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A