Recover Global Admin Microsoft account with lost MFA Access lockout

St James Treasurer 0 Reputation points
2026-05-14T18:34:25.3+00:00

I am unable to log in to my nonprofit tenant as the only global administrator account as my Microsoft Authenticator app backup failed causing all account registrations to be lost. There are no other global administrator accounts so I am totally locked out of the tenant.

Please could you assist with opening a Data Protection Team case - I see that @Raja Pothuraju has responded to a similar request previously.

I have also attempted calling the UK support number but it does not connect.

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Newest
  1. AI answer

    2026-05-14T18:35:12.35+00:00

    To recover access as the only Global Administrator who has lost Microsoft Authenticator/MFA access, the supported path is to work with Microsoft’s Data Protection / Tenant Recovery teams via Microsoft 365 support. Community moderators cannot directly open a case; only Microsoft support channels and Data Protection teams can perform tenant admin/MFA recovery after verifying identity.

    Follow these steps in order:

    1. Confirm there is truly no other Global Admin or partner
      • If any partner or other user has Global Administrator or Privileged Role Administrator rights through GDAP, they can promote another user to Global Admin or reset MFA without involving Microsoft:
        • See “Promote user to Global Administrator” scenarios in the tenant lockout guidance.
      • If there is absolutely no other GA and no partner with appropriate GDAP roles, proceed to step 2.
    2. Try Self-Service Password Reset (SSPR) if enabled
      • If Self-Service Password Reset is configured for the tenant, attempt recovery via the Self Service Password Reset tool.
      • If SSPR is not enabled or still requires the lost MFA method, continue to step 3.
    3. Contact Microsoft 365 / Data Protection support by phone
      • For scenarios where the only Global Admin is locked out and no other GA exists, Microsoft’s documented guidance is that the tenant owner/GA must contact Microsoft support directly.
      • Use the Microsoft 365 for business support phone numbers for the UK (or your region) from: Find Microsoft 365 for business support phone numbers by country or region.
      • When connected to support, clearly state:
        • This is a tenant lockout.
        • There is only one Global Administrator.
        • MFA is enforced and the only registered method (Microsoft Authenticator) is no longer accessible.
        • Request escalation to the Microsoft 365 Data Protection team (sometimes referred to as Data Protection / Tenant Recovery) to perform an admin MFA reset and restore access.
      • If the IVR is automated, use wording similar to what is described in the tenant admin MFA reset guidance (e.g., “Authenticator”, “Office 365 for business”, “company account”, “administrator”, “no other administrator”, “need to create a ticket, Data Protection Team”).
    4. If phone support fails to connect from the UK
      • Try again at a different time or from a different line, as some users report needing multiple attempts.
      • If still unable to reach a live agent, one documented workaround is:
        • Create a temporary new tenant by signing up for a Microsoft 365 trial.
        • In that new tenant’s admin center, open a support ticket and explicitly request to speak with the Data Protection team on behalf of the original nonprofit tenant that is locked out.
        • Provide all required verification (business documentation, domain ownership, nonprofit registration, etc.) so they can validate ownership and reset MFA for the original tenant’s Global Admin.
    5. Nonprofit-specific note
      • Microsoft for Nonprofits cannot bypass identity verification or directly restore tenant access. All tenant ownership and access decisions are handled through standard Microsoft 365 support and Data Protection processes.
      • Microsoft for Nonprofits can help prepare documentation and confirm eligibility, but the actual recovery still goes through Microsoft 365 support.
    6. After recovery
      • Once access is restored, implement the tenant lockout prevention best practices:
        • Ensure at least two Global Admin accounts with different credentials and MFA methods.
        • Configure break-glass emergency accounts excluded from Conditional Access, with strong passwords and monitored sign-ins.
        • Enable and configure Self-Service Password Reset (SSPR) and keep recovery methods up to date.
        • Review GDAP and partner relationships so a trusted partner can assist with future password/MFA resets if needed.

    These steps align with Microsoft’s documented process for single-Global-Admin tenant lockouts due to lost MFA.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.