A cloud-based identity and access management service for securing user authentication and resource access
There are two possible paths, depending on whether there is another administrator in the tenant.
- If there is another Global/Authentication admin in the tenant
Ask that admin to reset the locked-out admin’s MFA so it can be re-registered on a new device:
- Sign in to the Microsoft Entra admin center (https://entra.microsoft.com) as at least an Authentication Administrator or Global Administrator.
- Go to Entra ID → Users → select the locked-out admin account.
- Open Authentication methods.
- Select Require re-register multifactor authentication.
This clears the existing Microsoft Authenticator registrations. The next time the locked-out admin signs in, they will be prompted to set up MFA again and can register Microsoft Authenticator on the new phone.
If needed, the admin can also use Reset password on the same screen to issue a temporary password, and Revoke sessions to force reauthentication.
- If there is no other Global/Authentication admin (sole admin locked out)
This is a tenant lockout scenario. Forum moderators and documentation-based guidance cannot directly reset MFA for that account. In this case, Microsoft’s Data Protection / Tenant Recovery team must be engaged through a support ticket raised via Microsoft’s global customer service phone channels.
Required action:
• Call Microsoft global customer service using the appropriate regional number listed under “Customer service phone numbers - Microsoft Support”. • Clearly state that:
- This is a business/tenant account (Microsoft 365 / Microsoft Entra ID).
- The caller is the only Global Administrator.
- The admin is locked out due to Microsoft Authenticator / MFA and cannot access the admin portal to open a ticket.
- A Data Protection / Tenant Recovery case is needed to reset MFA/authentication methods for the tenant admin.
The frontline support agent will create a service request and route it to the Data Protection team, who will verify tenant ownership and then assist in resetting the MFA methods so that Microsoft Authenticator can be re-registered on a new device.
If direct phone contact is difficult, another documented workaround is to create a temporary trial tenant, sign in as admin there, and use that admin center to open a support ticket on behalf of the locked-out tenant, again requesting Data Protection involvement for MFA reset.
Note: For security reasons, there is no generic email address that can be used to request an MFA reset without going through the authenticated support channels and Data Protection verification process.
References:
- Manage user authentication methods for Microsoft Entra multifactor authentication
- Can't use Azure Multi-Factor Authentication to sign in to cloud services after you lose your phone or the phone number changes
- About administrator roles in the Microsoft 365 admin center
- Can't set up MFA because five devices are already registered to use an authenticator app
- Frequently asked questions about Microsoft Entra multifactor authentication
- Common problems with two-step verification for a work or school account
- Mandatory multifactor authentication for Azure and admin portals
- Global Admin Locked out - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- I need to reset my mfa methods - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A