Complete Microsoft 365 Tenant Lockout – Both Global Admin Accounts Locked Due to MFA – 8+ Days Without Recovery Assistance

Yash Agarwal 0 Reputation points
2026-05-13T06:26:53.1333333+00:00

We are experiencing a complete Microsoft 365 tenant lockout situation and urgently need escalation guidance.

Tenant: <PII REMOVED>

Issue: Both Global Administrator accounts became inaccessible due to MFA enforcement, resulting in a complete loss of access to:

  • Microsoft 365 Admin Center
  • Azure Portal
  • Teams administration
  • Billing
  • User management
  • All administrative controls

The tenant has now been inaccessible for more than 8 days and business operations at Paros Interactive Entertainment have been critically impacted.

Existing Support Cases:

  • <PII REMOVED>
  • <PII REMOVED>

Timeline:

  • The original support case was raised immediately after the lockout occurred.
  • We have repeatedly followed all instructions provided by Microsoft Support.
  • We created 2 separate alternate Microsoft accounts solely for the purpose of continuing the recovery process and raising additional support requests as instructed by Microsoft.
  • Microsoft has only contacted us once directly so far.
  • During that interaction, we were instructed to create another support case so the issue could supposedly be routed to the Data Recovery / Identity Verification team.
  • That interaction happened the day before yesterday, and since then we have still not received any callback, recovery engagement, or verification request.

At this stage, the issue does not appear to be receiving the urgency expected for a complete Global Administrator lockout causing total operational disruption.

We are fully prepared to complete any ownership verification required immediately.

We would sincerely appreciate:

  1. Guidance on the fastest escalation path for tenant recovery
  2. Assistance from Microsoft moderators or escalation engineers
  3. Confirmation if there is any direct route to the Data Recovery / Identity Verification team
  4. Any recommendations from users who have handled similar full-tenant lockout situations

Thank you.

Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Newest
  1. AI answer

    2026-05-13T06:27:27.78+00:00

    For a complete tenant lockout where all Global Administrators are blocked by MFA and no one can access the tenant, recovery must be handled directly by Microsoft’s Data Protection / Tenant Recovery team through a support case. Community moderators and product teams cannot bypass this process.

    Given the situation described (all GA accounts locked, no portal access, existing cases already opened), the supported path is:

    1. Ensure the scenario is clearly identified as a tenant lockout / only GA locked out
      In all existing and new support interactions, explicitly state that:
      • All Global Administrator accounts are locked due to MFA.
      • There is no other GA or break-glass account with access.
      • This is a full tenant lockout impacting business operations.
      Microsoft guidance is that in scenarios where the GA is locked out and there is no other GA, the case must be handled by Microsoft support / Data Protection to verify ownership and restore access. This is consistent with the tenant lockout guidance and the Q&A resolutions where moderators escalate to Data Protection / Tenant Recovery.
    2. Use phone-based Microsoft 365 business support to push escalation
      Since portal access is unavailable, use phone support to drive escalation:
      • Call the regional Microsoft 365 for business support number listed in:
        Find Microsoft 365 for business support phone numbers by country or region.
      • When prompted by the automated system or frontline agent, clearly answer along these lines (as documented in the Q&A guidance):
        • Problem type: “Authenticator” / MFA / can’t sign in.
        • Product: “Office 365 for business” / Microsoft 365 for business.
        • Account type: Company / organization.
        • Role: Administrator.
        • Other administrators: No (all GAs locked).
      • Ask explicitly for the case to be routed or escalated to the Data Protection / Tenant Recovery or Identity Verification team for Global Administrator lockout.
    3. If the tenant is via a partner, use the partner escalation path
      If the Microsoft 365 subscription is managed through a CSP/partner:
      • Contact the partner and request they open or escalate a service request on your behalf.
      • Partners with an active GDAP relationship and the Service Support Administrator role can create and escalate support requests for the customer tenant, as described in the GDAP tenant lockout guidance.
    4. Use an alternate tenant only as a channel to support (if needed)
      The Q&A guidance describes using a new trial tenant solely to open a support ticket when locked out of the original tenant:
      • Create a temporary Microsoft 365 trial tenant.
      • From that tenant’s admin center, open a support ticket that clearly states:
        • The issue concerns a different existing tenant (parosinteractive.com).
        • All GAs on that tenant are locked out due to MFA.
        • Provide the locked tenant’s domain, admin UPNs, and error messages.
      • This does not give access to the locked tenant but provides another route to reach Microsoft support and request escalation to Data Protection.
    5. Align with Microsoft’s tenant lockout and recovery guidance
      The official guidance for tenant lockouts and GA MFA issues is:
      • If another GA exists, that GA resets MFA or promotes a new GA.
      • If no other GA exists and SSPR / recovery options fail, the tenant owner / GA must contact Microsoft support, and Microsoft works directly with that GA through Data Protection / Tenant Recovery to verify identity and restore access.
      • Forum moderators can only escalate by creating a support ticket; they cannot directly modify accounts.
    6. For future prevention once access is restored
      After recovery, implement the recommended protections to avoid recurrence:
      • Create at least two cloud-only emergency access (“break-glass”) accounts with permanent Global Administrator role assignments, not federated or synced from on-premises.
      • Exclude at least one emergency account from all Conditional Access and MFA policies so that it always remains usable during MFA or federation outages.
      • Store credentials securely with dual control and configure monitoring/alerts for any sign-in by these accounts.
      • Ensure there are at least two normal GA accounts with different MFA methods and that Self-Service Password Reset (SSPR) is configured and tested.

    These steps align with Microsoft’s documented process: full tenant lockouts with no accessible GA must be resolved by Microsoft support / Data Protection after ownership verification; escalation is driven via phone support, partner support, or an alternate tenant used only as a support channel.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.