A cloud-based identity and access management service for securing user authentication and resource access
To restore access when the only Global Administrator is locked out due to MFA loss, Microsoft must handle the reset through the Data Protection team. Forum moderators and standard support channels cannot directly change MFA or passwords for security reasons.
Follow these steps:
- Contact Microsoft Data Protection / Support by phone
Use the regional business support numbers listed at:- Support for Business Products
- Or Find Microsoft 365 for business support phone numbers by country or region
- The problem is with Authenticator / MFA.
- The product is Office 365 / Microsoft 365 for business.
- The account is a company/organization (work or school) account.
- Confirm being the only Global Administrator for tenant
mdlcibalab2023.onmicrosoft.comand that sign-in is blocked by MFA.
- If the tenant is through a partner (CSP)
If the Microsoft 365 subscription was purchased via a Cloud Solution Provider (CSP) or partner, contact that partner and ask them to open a support ticket with Microsoft on behalf of the organization. Partners with GDAP and appropriate roles (for example, Privileged Authentication Administrator) may be able to reset passwords/MFA directly; otherwise, they must also involve Microsoft support. - If no direct access to support portal is available
If sign-in to any admin portal is impossible and there is no partner, an alternative is to create a temporary trial Microsoft 365 tenant, sign in as admin there, and from that tenant open a support ticket describing that the real production tenantmdlcibalab2023.onmicrosoft.comis locked and that the requester is its Global Admin. Be prepared to provide:- Admin UPN (masked in public, full value to support).
- Tenant domain:
mdlcibalab2023.onmicrosoft.com. - Organization name: MDL Cibalab EOOD.
- Error messages seen when attempting SMS/phone verification.
- Confirmation that there are no other global admins.
- Identity verification and MFA reset
After the ticket is routed, the Data Protection team will contact by email or phone, request documentation to prove ownership/administrative rights, and then:- Reset MFA for the Global Admin account, or
- Help regain access (for example, password reset plus MFA re-registration).
- Post-recovery recommendations
Once access is restored:- Add at least one more Global Administrator and a Privileged Authentication Administrator so a single-device failure does not lock the tenant again.
- Configure multiple MFA methods (Authenticator, SMS, phone call, possibly FIDO2/passkey or certificate-based authentication).
- Consider creating emergency access (“break-glass”) accounts excluded from Conditional Access and with strong, protected credentials, as described in the tenant lockout prevention guidance.
References:
- Troubleshoot sign-in issues and account access problems
- Preventing tenant lockouts
- Tenant Lockout: Scenarios & Next Steps
- Common problems with two-step verification for a work or school account
- About administrator roles in the Microsoft 365 admin center
- Mandatory multifactor authentication for Azure and admin portals
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- I need to reset my mfa methods - Microsoft Q&A
- Azure has blocked myphone number for SMS verification due to a “bad reputation” flag - Microsoft Q&A