Global Admin Lockout - MFA Reset Request - Tenant: PII

Velin Petrov 0 Reputation points
2026-05-08T13:18:45.86+00:00

To whom it may concern,

I am writing to request urgent assistance regarding a lockout from our Microsoft 365 Global Admin account: PII.

The issue: The primary administrator's mobile device suffered a hardware failure and underwent a factory reset. As a result, the Microsoft Authenticator app configuration was lost. We do not have backup codes available, and the alternative verification methods (SMS/Call) are currently failing with an error message on the Microsoft login page (as shown in the attached screenshot).

Tenant Details: PII

Domain: PII

Organization: MDL Cibalab EOOD

Admin Account: PII

As we are unable to access the Admin Center to reset the MFA settings ourselves, we request that your Data Protection Team contacts us to verify our identity and reset the MFA for the aforementioned account.

Please let us know what documentation is required to verify our ownership of this tenant.

Best regards,
Velin Petrov
System Administrator

Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Oldest
  1. AI answer

    2026-05-08T13:19:02.8933333+00:00

    To restore access when the only Global Administrator is locked out due to MFA loss, Microsoft must handle the reset through the Data Protection team. Forum moderators and standard support channels cannot directly change MFA or passwords for security reasons.

    Follow these steps:

    1. Contact Microsoft Data Protection / Support by phone
      Use the regional business support numbers listed at: When prompted by the automated system, clearly indicate:
      • The problem is with Authenticator / MFA.
      • The product is Office 365 / Microsoft 365 for business.
      • The account is a company/organization (work or school) account.
      • Confirm being the only Global Administrator for tenant mdlcibalab2023.onmicrosoft.com and that sign-in is blocked by MFA.
      The frontline agent will open a service request and route it to the Microsoft 365 Data Protection team (or Azure Data Protection team, depending on entry point). That team has specific tools and processes to verify identity and reset MFA or passwords for locked-out global admins.
    2. If the tenant is through a partner (CSP)
      If the Microsoft 365 subscription was purchased via a Cloud Solution Provider (CSP) or partner, contact that partner and ask them to open a support ticket with Microsoft on behalf of the organization. Partners with GDAP and appropriate roles (for example, Privileged Authentication Administrator) may be able to reset passwords/MFA directly; otherwise, they must also involve Microsoft support.
    3. If no direct access to support portal is available
      If sign-in to any admin portal is impossible and there is no partner, an alternative is to create a temporary trial Microsoft 365 tenant, sign in as admin there, and from that tenant open a support ticket describing that the real production tenant mdlcibalab2023.onmicrosoft.com is locked and that the requester is its Global Admin. Be prepared to provide:
      • Admin UPN (masked in public, full value to support).
      • Tenant domain: mdlcibalab2023.onmicrosoft.com.
      • Organization name: MDL Cibalab EOOD.
      • Error messages seen when attempting SMS/phone verification.
      • Confirmation that there are no other global admins.
    4. Identity verification and MFA reset
      After the ticket is routed, the Data Protection team will contact by email or phone, request documentation to prove ownership/administrative rights, and then:
      • Reset MFA for the Global Admin account, or
      • Help regain access (for example, password reset plus MFA re-registration).
    5. Post-recovery recommendations
      Once access is restored:
      • Add at least one more Global Administrator and a Privileged Authentication Administrator so a single-device failure does not lock the tenant again.
      • Configure multiple MFA methods (Authenticator, SMS, phone call, possibly FIDO2/passkey or certificate-based authentication).
      • Consider creating emergency access (“break-glass”) accounts excluded from Conditional Access and with strong, protected credentials, as described in the tenant lockout prevention guidance.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.