A cloud-based identity and access management service for securing user authentication and resource access
For a complete tenant lockout where all Global Administrators are blocked by MFA and no one can access the tenant, recovery must be handled directly by Microsoft’s Data Protection / Tenant Recovery team through a support case. Community moderators and product teams cannot bypass this process.
Given the situation described (all GA accounts locked, no portal access, existing cases already opened), the supported path is:
- Ensure the scenario is clearly identified as a tenant lockout / only GA locked out
In all existing and new support interactions, explicitly state that:- All Global Administrator accounts are locked due to MFA.
- There is no other GA or break-glass account with access.
- This is a full tenant lockout impacting business operations.
- Use phone-based Microsoft 365 business support to push escalation
Since portal access is unavailable, use phone support to drive escalation:- Call the regional Microsoft 365 for business support number listed in:
Find Microsoft 365 for business support phone numbers by country or region. - When prompted by the automated system or frontline agent, clearly answer along these lines (as documented in the Q&A guidance):
- Problem type: “Authenticator” / MFA / can’t sign in.
- Product: “Office 365 for business” / Microsoft 365 for business.
- Account type: Company / organization.
- Role: Administrator.
- Other administrators: No (all GAs locked).
- Ask explicitly for the case to be routed or escalated to the Data Protection / Tenant Recovery or Identity Verification team for Global Administrator lockout.
- Call the regional Microsoft 365 for business support number listed in:
- If the tenant is via a partner, use the partner escalation path
If the Microsoft 365 subscription is managed through a CSP/partner:- Contact the partner and request they open or escalate a service request on your behalf.
- Partners with an active GDAP relationship and the Service Support Administrator role can create and escalate support requests for the customer tenant, as described in the GDAP tenant lockout guidance.
- Use an alternate tenant only as a channel to support (if needed)
The Q&A guidance describes using a new trial tenant solely to open a support ticket when locked out of the original tenant:- Create a temporary Microsoft 365 trial tenant.
- From that tenant’s admin center, open a support ticket that clearly states:
- The issue concerns a different existing tenant (parosinteractive.com).
- All GAs on that tenant are locked out due to MFA.
- Provide the locked tenant’s domain, admin UPNs, and error messages.
- This does not give access to the locked tenant but provides another route to reach Microsoft support and request escalation to Data Protection.
- Align with Microsoft’s tenant lockout and recovery guidance
The official guidance for tenant lockouts and GA MFA issues is:- If another GA exists, that GA resets MFA or promotes a new GA.
- If no other GA exists and SSPR / recovery options fail, the tenant owner / GA must contact Microsoft support, and Microsoft works directly with that GA through Data Protection / Tenant Recovery to verify identity and restore access.
- Forum moderators can only escalate by creating a support ticket; they cannot directly modify accounts.
- For future prevention once access is restored
After recovery, implement the recommended protections to avoid recurrence:- Create at least two cloud-only emergency access (“break-glass”) accounts with permanent Global Administrator role assignments, not federated or synced from on-premises.
- Exclude at least one emergency account from all Conditional Access and MFA policies so that it always remains usable during MFA or federation outages.
- Store credentials securely with dual control and configure monitoring/alerts for any sign-in by these accounts.
- Ensure there are at least two normal GA accounts with different MFA methods and that Self-Service Password Reset (SSPR) is configured and tested.
These steps align with Microsoft’s documented process: full tenant lockouts with no accessible GA must be resolved by Microsoft support / Data Protection after ownership verification; escalation is driven via phone support, partner support, or an alternate tenant used only as a support channel.
References:
- Preventing tenant lockouts
- Tenant Lockout: Scenarios & Next Steps
- Checklist for Tenant Setup and GDAP Management
- Privileged Access
- Create a resilient access control management strategy with Microsoft Entra ID
- Mandatory multifactor authentication for Azure and admin portals
- Global Admin Locked out - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- I need to reset my mfa methods - Microsoft Q&A
- Azure has blocked myphone number for SMS verification due to a “bad reputation” flag - Microsoft Q&A
- Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A