Urgent Azure / Microsoft Entra tenant compromise situation. How to get urgent Support

Azeem Ahmad 0 Reputation points
2026-05-16T06:25:53.56+00:00

An unauthorized Global Administrator account was added to our tenant, while legitimate Global Admin accounts appear to have had passwords/MFA changed. Azure subscription RBAC access was also removed from legitimate admins.

We still retain limited tenant-level access through a lower-privileged account but cannot recover administrative control.

Our support plan is Basic, and we are struggling to reach the correct escalation path during the weekend.

Looking for guidance on:

fastest way to reach Microsoft Data Protection Team

emergency tenant recovery escalation

restoring Global Administrator access after compromise

This is affecting a live production environment.

Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Newest
  1. AI answer

    2026-05-16T06:26:11.12+00:00

    Follow these steps immediately to contain the incident and get Microsoft involved as fast as possible.

    1. Urgently contact Microsoft Support / Data Protection
    • Use the Microsoft 365 for business support phone channel to reach a live agent and request escalation to the Data Protection team for a tenant compromise and admin lockout scenario. Phone numbers by country/region are listed here: Find Microsoft 365 for business support phone numbers by country or region.
    • When speaking to support, clearly state:
      • The tenant is compromised.
      • A rogue Global Administrator was added.
      • Legitimate Global Administrators lost access (password/MFA changed, RBAC removed).
      • Only low-privilege access remains.
      • This is production-impacting and requires Data Protection / security escalation.
    • If the IVR is automated, use wording similar to:
      • Product: “Office 365 for business” / “Microsoft 365 for business”
      • Account type: “Company account”
      • Role: “Yes, administrator; no, there is no other administrator”
      • Request: “I need to create a ticket and be routed to the Data Protection team for a compromised tenant and admin lockout.”
    • If front-line support is not routing correctly, explicitly ask for a duty manager and request escalation to the Data Protection team, as described in similar MFA lockout cases.
    1. Use any remaining access to contain and investigate While waiting for Microsoft escalation, use the remaining low-privilege account (and any still-working admin paths) to:
    • Change credentials for all known admin identities and Azure RBAC owners where possible:
    • Review and correct admin recovery details:
      • In Microsoft Entra ID, review password recovery emails and phone numbers for admin accounts and update if they were tampered with.
    • Identify scope of compromise:
    1. Work with Microsoft to restore Global Administrator control When in contact with the Data Protection / security team:
    • Provide:
      • Tenant ID, domain(s), subscription IDs.
      • Timeline of when the rogue Global Administrator appeared and when legitimate admins lost access.
      • Evidence of suspicious sign-ins and changes (if logs are still accessible).
    • Request:
      • Removal or disablement of the unauthorized Global Administrator.
      • Reset of authentication methods and passwords for legitimate Global Administrators.
      • Restoration or recreation of Azure RBAC Owner/Contributor assignments for subscriptions.
    • Follow their identity verification process; this may involve multiple calls and documentation but is the supported path for emergency tenant recovery when Global Admins are locked out.
    1. Post-recovery hardening (after control is regained) Once Global Administrator access is restored and the incident is contained, implement the following to reduce future risk:
    • Create at least two cloud-only emergency access (“break-glass”) accounts:
      • Permanently assign the Global Administrator role.
      • Ensure they are cloud-only (not federated or synced) and not tied to individuals.
      • Use long, randomly generated passwords (32+ characters) configured to never expire, with dual control over credential storage (for example, split and stored in separate secure physical locations).
      • Follow the detailed guidance in Manage emergency access accounts in Microsoft Entra ID.
    • Configure Conditional Access so that:
      • At least one emergency account is excluded from all Conditional Access and MFA policies to guarantee access during outages or lockouts.
      • The second emergency account can use strong, phishing-resistant methods such as FIDO2 security keys.
    • Enable monitoring and alerting for emergency and privileged accounts:
      • Use Azure Monitor or Microsoft Sentinel to alert on any sign-in or configuration change involving emergency accounts and Global Administrators.
      • Configure alerts (email/SMS) to security operations and leadership so any emergency account use triggers an immediate investigation.
    • Implement Privileged Identity Management (PIM) and approval workflows:
      • Require approval for Global Administrator activation to reduce the risk of silent privilege escalation by attackers.

    These steps provide an immediate escalation path (Data Protection via phone support) and a concrete plan to restore and then harden Global Administrator access after a compromise.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.