Tenant lockout — Azure AD B2C tenant — no accessible administrator

Khalid ERRABTI 0 Reputation points
2026-05-20T09:28:53.2333333+00:00

We have lost administrative access to an Azure AD B2C tenant. No native Global Administrator account is reachable, and a guest administrator (PII) cannot complete MFA (error 500121, MFA registered on an inaccessible device). Cross-tenant access settings cannot reach this tenant ("Unable to find tenant" when adding the tenant ID from another Entra directory), consistent with it being a B2C tenant.

Affected tenant:

  • Name: WacomosB2C
  • Tenant ID: PII
  • Primary domain: PII

Requesting Data Protection / Tenant Recovery escalation. We can verify ownership via Azure subscription billing details and/or DNS TXT record on a domain we control.

Requesting party: PII(Global Administrator, — the partner/managing tenant).

Microsoft Security | Microsoft Entra | Microsoft Entra External ID

1 answer

Sort by: Newest
  1. AI answer

    2026-05-20T09:29:09.98+00:00

    Administrative access to the Azure AD B2C tenant cannot be restored through configuration changes or cross-tenant access alone in this situation. The only supported path is escalation to Microsoft Support so the Data Protection / Tenant Recovery team can verify ownership and reset credentials/MFA for an administrator.

    Based on the documented patterns and similar resolved cases, the required steps are:

    1. Open a support case to reach the Data Protection / Tenant Recovery team
      • A tenant where no Global Administrator is reachable and MFA cannot be completed (single admin, lost device, or only guest admin blocked by MFA) is treated as a tenant lockout scenario.
      • When no admin can sign in to open a ticket from the affected tenant, use one of these options (whichever applies):
        • Call Microsoft support using the global support phone numbers: see global support phone numbers.
        • If there is a separate Microsoft 365/Azure tenant where an administrator can sign in (for example, the alexsys.solutions managing tenant), sign in there and open a support ticket, clearly stating that the issue is a lockout from a different Azure AD B2C tenant and that Data Protection / Tenant Recovery involvement is required.
        • If no paid subscription is available to open a ticket, create a new trial tenant/subscription and use it only to submit the support request, explicitly indicating that the problem concerns another existing tenant that is locked.
    2. Clearly describe the scenario in the support request Include, at minimum:
      • That this is a tenant lockout for an Azure AD B2C tenant.
      • Tenant name: WacomosB2C.
      • Tenant ID: 66ec31dc-2e52-4041-b877-4772278b2e88.
      • Primary domain: alexsysSolutionswcmsb2c.onmicrosoft.com.
      • That no native Global Administrator is reachable and the only known admin (guest) cannot complete MFA due to error 500121 (Authenticator on an inaccessible device).
      • That the requesting party is a Global Administrator in the managing/partner tenant and can verify ownership via Azure subscription billing details and/or DNS TXT record on a controlled domain.
      • Explicitly request Data Protection / Tenant Recovery escalation to reset MFA/credentials for an administrator account on the B2C tenant.
    3. Complete identity and ownership verification
      • The Data Protection team has specific tools and processes to verify identity and ownership when there is only one admin or no accessible admin.
      • Be prepared to:
        • Prove control of domains associated with the tenant (for example, by adding a DNS TXT record as instructed by support).
        • Provide subscription/billing information if the tenant is linked to an Azure subscription.
        • Provide any other documentation support requests (business registration, contact details, etc.).
    4. Wait for Data Protection to complete the recovery
      • Once the case is escalated, avoid opening duplicate requests; this is explicitly recommended for tenant inaccessibility scenarios.
      • Data Protection will either:
        • Reset credentials/MFA for an existing admin account, or
        • Provide another supported recovery path so that an administrator can regain access.
    5. After recovery, prevent future lockouts For Azure AD B2C tenants, follow the documented best practices:
      • Create at least two emergency access accounts that:
        • Are not tied to individual employees or their personal devices.
        • Use strong authentication that differs from normal admin accounts.
        • Are excluded from restrictive Conditional Access policies.
        • Use credentials/devices that do not expire or get cleaned up due to inactivity.
      • Regularly review admin accounts and roles for activity and validity, and remove stale admin accounts.

    These steps align with the documented guidance for:

    • Tenant lockout scenarios where no other global admin can reset MFA.
    • Cases where the Data Protection team is explicitly engaged to restore access.
    • Preventing future lockouts in Azure AD B2C by using emergency access accounts.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.