A cloud-based identity and access management service for securing user authentication and resource access
Follow these steps immediately to contain the incident and get Microsoft involved as fast as possible.
- Urgently contact Microsoft Support / Data Protection
- Use the Microsoft 365 for business support phone channel to reach a live agent and request escalation to the Data Protection team for a tenant compromise and admin lockout scenario. Phone numbers by country/region are listed here: Find Microsoft 365 for business support phone numbers by country or region.
- When speaking to support, clearly state:
- The tenant is compromised.
- A rogue Global Administrator was added.
- Legitimate Global Administrators lost access (password/MFA changed, RBAC removed).
- Only low-privilege access remains.
- This is production-impacting and requires Data Protection / security escalation.
- If the IVR is automated, use wording similar to:
- Product: “Office 365 for business” / “Microsoft 365 for business”
- Account type: “Company account”
- Role: “Yes, administrator; no, there is no other administrator”
- Request: “I need to create a ticket and be routed to the Data Protection team for a compromised tenant and admin lockout.”
- If front-line support is not routing correctly, explicitly ask for a duty manager and request escalation to the Data Protection team, as described in similar MFA lockout cases.
- Use any remaining access to contain and investigate While waiting for Microsoft escalation, use the remaining low-privilege account (and any still-working admin paths) to:
- Change credentials for all known admin identities and Azure RBAC owners where possible:
- Update passwords following Password policy recommendations.
- Ensure all remaining tenant admins and RBAC owners have MFA registered and enforced where still under your control.
- Review and correct admin recovery details:
- In Microsoft Entra ID, review password recovery emails and phone numbers for admin accounts and update if they were tampered with.
- Identify scope of compromise:
- In the Azure portal, review which users, tenants, and subscriptions are at risk.
- Use Microsoft Entra ID Protection risk reports to see risky users and risky sign-ins and start remediation: Investigate risk Microsoft Entra ID Protection.
- Work with Microsoft to restore Global Administrator control When in contact with the Data Protection / security team:
- Provide:
- Tenant ID, domain(s), subscription IDs.
- Timeline of when the rogue Global Administrator appeared and when legitimate admins lost access.
- Evidence of suspicious sign-ins and changes (if logs are still accessible).
- Request:
- Removal or disablement of the unauthorized Global Administrator.
- Reset of authentication methods and passwords for legitimate Global Administrators.
- Restoration or recreation of Azure RBAC Owner/Contributor assignments for subscriptions.
- Follow their identity verification process; this may involve multiple calls and documentation but is the supported path for emergency tenant recovery when Global Admins are locked out.
- Post-recovery hardening (after control is regained) Once Global Administrator access is restored and the incident is contained, implement the following to reduce future risk:
- Create at least two cloud-only emergency access (“break-glass”) accounts:
- Permanently assign the Global Administrator role.
- Ensure they are cloud-only (not federated or synced) and not tied to individuals.
- Use long, randomly generated passwords (32+ characters) configured to never expire, with dual control over credential storage (for example, split and stored in separate secure physical locations).
- Follow the detailed guidance in Manage emergency access accounts in Microsoft Entra ID.
- Configure Conditional Access so that:
- At least one emergency account is excluded from all Conditional Access and MFA policies to guarantee access during outages or lockouts.
- The second emergency account can use strong, phishing-resistant methods such as FIDO2 security keys.
- Enable monitoring and alerting for emergency and privileged accounts:
- Use Azure Monitor or Microsoft Sentinel to alert on any sign-in or configuration change involving emergency accounts and Global Administrators.
- Configure alerts (email/SMS) to security operations and leadership so any emergency account use triggers an immediate investigation.
- Implement Privileged Identity Management (PIM) and approval workflows:
- Require approval for Global Administrator activation to reduce the risk of silent privilege escalation by attackers.
These steps provide an immediate escalation path (Data Protection via phone support) and a concrete plan to restore and then harden Global Administrator access after a compromise.
References:
- Detect and respond to security alerts
- Tenant Lockout: Scenarios & Next Steps
- Privileged Access
- Manage emergency access accounts in Microsoft Entra ID
- Configure Microsoft Entra for Zero Trust: Protect engineering systems
- Secure Configuration Guide
- How Do I Regain Access to My Account After Losing Access to Microsoft Authenticator? (Urgent Request). - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A