Managing external identities to enable secure access for partners, customers, and other non-employees
Administrative access to the Azure AD B2C tenant cannot be restored through configuration changes or cross-tenant access alone in this situation. The only supported path is escalation to Microsoft Support so the Data Protection / Tenant Recovery team can verify ownership and reset credentials/MFA for an administrator.
Based on the documented patterns and similar resolved cases, the required steps are:
- Open a support case to reach the Data Protection / Tenant Recovery team
- A tenant where no Global Administrator is reachable and MFA cannot be completed (single admin, lost device, or only guest admin blocked by MFA) is treated as a tenant lockout scenario.
- When no admin can sign in to open a ticket from the affected tenant, use one of these options (whichever applies):
- Call Microsoft support using the global support phone numbers: see global support phone numbers.
- If there is a separate Microsoft 365/Azure tenant where an administrator can sign in (for example, the alexsys.solutions managing tenant), sign in there and open a support ticket, clearly stating that the issue is a lockout from a different Azure AD B2C tenant and that Data Protection / Tenant Recovery involvement is required.
- If no paid subscription is available to open a ticket, create a new trial tenant/subscription and use it only to submit the support request, explicitly indicating that the problem concerns another existing tenant that is locked.
- Clearly describe the scenario in the support request
Include, at minimum:
- That this is a tenant lockout for an Azure AD B2C tenant.
- Tenant name:
WacomosB2C. - Tenant ID:
66ec31dc-2e52-4041-b877-4772278b2e88. - Primary domain:
alexsysSolutionswcmsb2c.onmicrosoft.com. - That no native Global Administrator is reachable and the only known admin (guest) cannot complete MFA due to error 500121 (Authenticator on an inaccessible device).
- That the requesting party is a Global Administrator in the managing/partner tenant and can verify ownership via Azure subscription billing details and/or DNS TXT record on a controlled domain.
- Explicitly request Data Protection / Tenant Recovery escalation to reset MFA/credentials for an administrator account on the B2C tenant.
- Complete identity and ownership verification
- The Data Protection team has specific tools and processes to verify identity and ownership when there is only one admin or no accessible admin.
- Be prepared to:
- Prove control of domains associated with the tenant (for example, by adding a DNS TXT record as instructed by support).
- Provide subscription/billing information if the tenant is linked to an Azure subscription.
- Provide any other documentation support requests (business registration, contact details, etc.).
- Wait for Data Protection to complete the recovery
- Once the case is escalated, avoid opening duplicate requests; this is explicitly recommended for tenant inaccessibility scenarios.
- Data Protection will either:
- Reset credentials/MFA for an existing admin account, or
- Provide another supported recovery path so that an administrator can regain access.
- After recovery, prevent future lockouts
For Azure AD B2C tenants, follow the documented best practices:
- Create at least two emergency access accounts that:
- Are not tied to individual employees or their personal devices.
- Use strong authentication that differs from normal admin accounts.
- Are excluded from restrictive Conditional Access policies.
- Use credentials/devices that do not expire or get cleaned up due to inactivity.
- Regularly review admin accounts and roles for activity and validity, and remove stale admin accounts.
- Create at least two emergency access accounts that:
These steps align with the documented guidance for:
- Tenant lockout scenarios where no other global admin can reset MFA.
- Cases where the Data Protection team is explicitly engaged to restore access.
- Preventing future lockouts in Azure AD B2C by using emergency access accounts.
References:
- Preventing tenant lockouts
- Tenant inaccessible due to inactivity
- Discover your Microsoft cloud footprint FAQ
- Manage emergency access accounts in Azure Active Directory B2C
- Azure AD B2C: Frequently asked questions (FAQ)
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- Global Admin Locked out - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A