A cloud-based identity and access management service for securing user authentication and resource access
Because all admins and break-glass accounts are locked out by a misconfigured Conditional Access policy, recovery must go through Microsoft support.
Use the following steps:
- Verify that no other admin still has access
- If any administrator can still sign in (for example, an account not covered by the policy), that admin can go to Microsoft Entra admin center → Protection → Conditional Access → Policies and disable or edit the blocking policies.
- If no admin can sign in (full tenant lockout)
- This matches the documented “locked out because of an incorrect setting in a Conditional Access policy” scenario.
- In this case, an admin must open a support case with Microsoft so support can adjust the Conditional Access policies on the tenant’s behalf.
- Follow the documented guidance to submit a support request as described in the article on troubleshooting Conditional Access lockouts. Microsoft support will review and, after confirming the lockout, update or disable the policies that are preventing access.
- After access is restored
- Sign in with a Global Administrator or Conditional Access Administrator account.
- Review and correct the problematic Conditional Access policies.
- Ensure at least two emergency access (break-glass) accounts exist and are excluded from all Conditional Access policies, as recommended in the planning and policy documents.
- Validate new or modified policies in Report-only mode before enabling them to avoid future tenant-wide lockouts.
References: