A cloud-based identity and access management service for securing user authentication and resource access
For a complete tenant lockout where the only Global Administrator is unable to complete MFA and no alternative methods are available, resolution requires direct engagement with Microsoft support and escalation to the Data Protection/Tenant Recovery team. This cannot be fixed from the portal or by self-service tools when there is no other Global Administrator.
Based on the documented patterns for similar cases:
- If there is any other Global Administrator or privileged account in the tenant (even a guest GA in a related tenant), that admin can:
- Sign in to the Microsoft Entra admin center.
- Go to Identity > Users > All users.
- Select the locked-out Global Admin account.
- Open Authentication methods.
- Select Require re-register multifactor authentication.
- After this, the locked-out admin signs in again and is prompted to register MFA from scratch.
- If there is truly no other Global Administrator with access (single-admin tenant lockout):
- This is treated as a tenant lockout scenario.
- The only supported path is to open a support case and have it escalated to the Data Protection (DP) / Tenant Recovery team.
- The DP team verifies tenant ownership and, once verified, can reset or re-register MFA for at least one admin account so that access to the tenant is restored.
- How similar cases have been resolved:
- In comparable incidents where the only Global Admin lost access to Microsoft Authenticator and had no backup methods, support agents escalated the ticket to the Data Protection team, who then contacted the admin via phone or email, performed identity verification, and reset MFA or added an additional authentication method.
- In another case, support worked with the customer to create or use another Global Administrator account (for example, a guest GA in a related tenant), then used that account to perform Require re-register MFA on the locked-out user.
- Next steps:
- Use any available Microsoft 365/Azure support channel (phone support is recommended in lockout scenarios) to open a support ticket for tenant lockout / MFA lockout.
- Clearly state that:
- There is a complete tenant lockout.
- There is only one Global Administrator.
- MFA is enforced and the only registered method (Microsoft Authenticator) is inaccessible.
- No alternative verification methods (SMS, email, other app) are configured.
- Request escalation to the Data Protection/Tenant Recovery team for MFA reset and tenant recovery.
- Be prepared to provide business and identity verification information as requested by the support engineer.
Once the Data Protection team completes verification, they can reset MFA or add another method so that the Global Administrator can sign in again and regain control of the tenant.
References:
- Preventing tenant lockouts
- Manage emergency access accounts in Microsoft Entra ID
- You don't receive a text or voice call that contains the verification code for Microsoft Entra multifactor authentication
- Mandatory multifactor authentication for Azure and admin portals
- Common problems with two-step verification for a work or school account
- Global Admin Locked out - Microsoft Q&A
- Reset Personal Azure MFA - Microsoft Q&A
- How Do I Regain Access to My Account After Losing Access to Microsoft Authenticator? (Urgent Request). - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- I need to reset my mfa methods - Microsoft Q&A