URGENT: Complete Tenant Lockout / MFA Reset Required for Global Admin

Syed Mohd Ali 0 Reputation points
2026-05-09T16:00:28.7133333+00:00

Hello,

I am experiencing a complete tenant lockout on my personal Azure/Entra ID account.

I am the sole Global Administrator for this tenant. The Azure portal is prompting me for a 6-digit Authenticator code, but my app only has my personal 8-digit profile. I am not receiving push notifications, and there are no alternative sign-in methods available on the "Verify your identity" screen (no SMS or email backup).

Because I am the only admin and have no other ways to verify, I am caught in an MFA loop and cannot access my Azure resources.

I am trying to log into my personal Azure subscription. After the initial authentication, it asks for a code from Authenticator.

The Authenticator app shows 8‑digit codes, but Azure expects 6‑digit codes - Push notifications never arrive - “Use another verification option” doesn’t appear - The MFA reset page ([aka.ms/mfasetup]) only works for work/school accounts.

I tried clicking “I can’t use my authenticator app right now.” - Appears to be Azure MFA profile is likely stuck.

Need help to reset personal azure MFA for my account

Please escalate this ticket immediately to the Data Protection Team so they can verify my identity and perform a backend MFA reset for my Entra ID tenant.

Best regards,
Syed Ali

Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Oldest
  1. AI answer

    2026-05-09T16:00:43.6+00:00

    For a complete tenant lockout where the only Global Administrator is unable to complete MFA and no alternative methods are available, resolution requires direct engagement with Microsoft support and escalation to the Data Protection/Tenant Recovery team. This cannot be fixed from the portal or by self-service tools when there is no other Global Administrator.

    Based on the documented patterns for similar cases:

    1. If there is any other Global Administrator or privileged account in the tenant (even a guest GA in a related tenant), that admin can:
      • Sign in to the Microsoft Entra admin center.
      • Go to Identity > Users > All users.
      • Select the locked-out Global Admin account.
      • Open Authentication methods.
      • Select Require re-register multifactor authentication.
      • After this, the locked-out admin signs in again and is prompted to register MFA from scratch.
    2. If there is truly no other Global Administrator with access (single-admin tenant lockout):
      • This is treated as a tenant lockout scenario.
      • The only supported path is to open a support case and have it escalated to the Data Protection (DP) / Tenant Recovery team.
      • The DP team verifies tenant ownership and, once verified, can reset or re-register MFA for at least one admin account so that access to the tenant is restored.
    3. How similar cases have been resolved:
      • In comparable incidents where the only Global Admin lost access to Microsoft Authenticator and had no backup methods, support agents escalated the ticket to the Data Protection team, who then contacted the admin via phone or email, performed identity verification, and reset MFA or added an additional authentication method.
      • In another case, support worked with the customer to create or use another Global Administrator account (for example, a guest GA in a related tenant), then used that account to perform Require re-register MFA on the locked-out user.
    4. Next steps:
      • Use any available Microsoft 365/Azure support channel (phone support is recommended in lockout scenarios) to open a support ticket for tenant lockout / MFA lockout.
      • Clearly state that:
        • There is a complete tenant lockout.
        • There is only one Global Administrator.
        • MFA is enforced and the only registered method (Microsoft Authenticator) is inaccessible.
        • No alternative verification methods (SMS, email, other app) are configured.
      • Request escalation to the Data Protection/Tenant Recovery team for MFA reset and tenant recovery.
      • Be prepared to provide business and identity verification information as requested by the support engineer.

    Once the Data Protection team completes verification, they can reset MFA or add another method so that the Global Administrator can sign in again and regain control of the tenant.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.