A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
To recover access as the only Global Administrator who has lost Microsoft Authenticator/MFA access, the supported path is to work with Microsoft’s Data Protection / Tenant Recovery teams via Microsoft 365 support. Community moderators cannot directly open a case; only Microsoft support channels and Data Protection teams can perform tenant admin/MFA recovery after verifying identity.
Follow these steps in order:
- Confirm there is truly no other Global Admin or partner
- If any partner or other user has Global Administrator or Privileged Role Administrator rights through GDAP, they can promote another user to Global Admin or reset MFA without involving Microsoft:
- See “Promote user to Global Administrator” scenarios in the tenant lockout guidance.
- If there is absolutely no other GA and no partner with appropriate GDAP roles, proceed to step 2.
- If any partner or other user has Global Administrator or Privileged Role Administrator rights through GDAP, they can promote another user to Global Admin or reset MFA without involving Microsoft:
- Try Self-Service Password Reset (SSPR) if enabled
- If Self-Service Password Reset is configured for the tenant, attempt recovery via the Self Service Password Reset tool.
- If SSPR is not enabled or still requires the lost MFA method, continue to step 3.
- Contact Microsoft 365 / Data Protection support by phone
- For scenarios where the only Global Admin is locked out and no other GA exists, Microsoft’s documented guidance is that the tenant owner/GA must contact Microsoft support directly.
- Use the Microsoft 365 for business support phone numbers for the UK (or your region) from: Find Microsoft 365 for business support phone numbers by country or region.
- When connected to support, clearly state:
- This is a tenant lockout.
- There is only one Global Administrator.
- MFA is enforced and the only registered method (Microsoft Authenticator) is no longer accessible.
- Request escalation to the Microsoft 365 Data Protection team (sometimes referred to as Data Protection / Tenant Recovery) to perform an admin MFA reset and restore access.
- If the IVR is automated, use wording similar to what is described in the tenant admin MFA reset guidance (e.g., “Authenticator”, “Office 365 for business”, “company account”, “administrator”, “no other administrator”, “need to create a ticket, Data Protection Team”).
- If phone support fails to connect from the UK
- Try again at a different time or from a different line, as some users report needing multiple attempts.
- If still unable to reach a live agent, one documented workaround is:
- Create a temporary new tenant by signing up for a Microsoft 365 trial.
- In that new tenant’s admin center, open a support ticket and explicitly request to speak with the Data Protection team on behalf of the original nonprofit tenant that is locked out.
- Provide all required verification (business documentation, domain ownership, nonprofit registration, etc.) so they can validate ownership and reset MFA for the original tenant’s Global Admin.
- Nonprofit-specific note
- Microsoft for Nonprofits cannot bypass identity verification or directly restore tenant access. All tenant ownership and access decisions are handled through standard Microsoft 365 support and Data Protection processes.
- Microsoft for Nonprofits can help prepare documentation and confirm eligibility, but the actual recovery still goes through Microsoft 365 support.
- After recovery
- Once access is restored, implement the tenant lockout prevention best practices:
- Ensure at least two Global Admin accounts with different credentials and MFA methods.
- Configure break-glass emergency accounts excluded from Conditional Access, with strong passwords and monitored sign-ins.
- Enable and configure Self-Service Password Reset (SSPR) and keep recovery methods up to date.
- Review GDAP and partner relationships so a trusted partner can assist with future password/MFA resets if needed.
- Once access is restored, implement the tenant lockout prevention best practices:
These steps align with Microsoft’s documented process for single-Global-Admin tenant lockouts due to lost MFA.
References:
- Tenant access recovery
- Troubleshoot sign-in issues and account access problems
- Preventing tenant lockouts
- Common problems with two-step verification for a work or school account
- Global Admin Locked out - Microsoft Q&A
- How Do I Regain Access to My Account After Losing Access to Microsoft Authenticator? (Urgent Request). - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- I need to reset my mfa methods - Microsoft Q&A