A cloud-based identity and access management service for securing user authentication and resource access
Yes. When the only global administrator has lost or can’t use the MFA method and can’t access the admin portals, MFA can be reset by Microsoft’s Data Protection team.
Process summary:
- Confirm there is no other global admin
- If there were another global administrator, that admin could sign in to the Microsoft Entra admin center and select the affected user → Authentication methods → Require re-register multifactor authentication to reset MFA.
- In this scenario, there is only one global admin, so this option is not available.
- Contact Microsoft Support and reach the Data Protection team
- Use the official Customer service phone numbers - Microsoft Support channel referenced in the documentation.
- When calling, clearly state:
- The issue is with Authenticator / MFA.
- The product is Office 365 / Microsoft 365 for business or Microsoft Entra ID.
- It is a company/organization account.
- The caller is the only global administrator and is locked out due to lost/unusable MFA.
- A service request is needed and must be routed to the Data Protection team (or Tenant Recovery/Data Protection) to reset MFA for the tenant admin.
- The Data Protection team will use their verification process (tenant ownership and identity checks) and, once validated, can reset the MFA registration for the global admin so a new MFA method can be configured.
- Alternative escalation path if phone support cannot be reached
- Create a temporary trial tenant (for example, a Microsoft 365 trial) and sign in as its admin.
- From that new tenant’s admin center, open a support ticket explaining that access to a different, existing tenant is lost because the only global admin’s MFA is unavailable.
- Ask that the case be escalated to the Data Protection team for MFA reset and tenant recovery on the original tenant.
After Data Protection completes the process and resets MFA, sign in again to the original tenant, re-register MFA (for example, Microsoft Authenticator), and consider adding additional authentication methods to avoid future lockouts.
References:
- Manage user authentication methods for Microsoft Entra multifactor authentication
- Can't use Azure Multi-Factor Authentication to sign in to cloud services after you lose your phone or the phone number changes
- Can't set up MFA because five devices are already registered to use an authenticator app
- Common problems with two-step verification for a work or school account
- Global Admin Locked out - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A